CVE-2023-26089
02.05.2023, 20:15
European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5.Enginsight
Vendor | Product | Version |
---|---|---|
echa.europa | iuclid | 5.15.0 ≤ 𝑥 < 6.27.6 |
𝑥
= Vulnerable software versions
References