CVE-2023-46943
13.01.2024, 02:15
An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generating tokens is hardcoded as "secret". A weak HMAC secret poses a risk because attackers can use the predictable secret to create valid JSON Web Tokens (JWTs), allowing them access to important information and actions within the application.Enginsight
Vendor | Product | Version |
---|---|---|
evershop | evershop | 1.0.0:beta |
evershop | evershop | 1.0.0:beta1 |
evershop | evershop | 1.0.0:beta2 |
evershop | evershop | 1.0.0:beta3 |
evershop | evershop | 1.0.0:beta4 |
evershop | evershop | 1.0.0:beta5 |
evershop | evershop | 1.0.0:rc1 |
evershop | evershop | 1.0.0:rc2 |
evershop | evershop | 1.0.0:rc3 |
evershop | evershop | 1.0.0:rc5 |
evershop | evershop | 1.0.0:rc6 |
evershop | evershop | 1.0.0:rc7 |
𝑥
= Vulnerable software versions