CVE-2023-48396
30.07.2024, 09:15
Web Authentication vulnerability in Apache SeaTunnel.Since the jwt key is hardcoded in the application, an attacker can forge any token to log in any user. Attacker can getsecret key in/seatunnel-server/seatunnel-app/src/main/resources/application.yml and then create a token. This issue affects Apache SeaTunnel: 1.0.0. Users are recommended to upgrade to version 1.0.1, which fixes the issue.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration