Description
Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability allows attackers to authenticate to the application via a crafted JWT token.
Remediation
References
https://github.com/xubowenW/JWTissues/blob/main/lamp%20issue.md
https://github.com/dromara/lamp-cloud/issues/183
Related Vulnerabilities
CVE-2020-7738 Vulnerability in npm package shiba
CVE-2019-14262 Vulnerability in maven package com.drewnoakes:metadata-extractor
CVE-2019-14517 Vulnerability in npm package editor.md
CVE-2018-20676 Vulnerability in npm package bootstrap-sass
CVE-2023-49620 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-common