CVE-2024-46508
EUVD-2024-5557108.05.2026, 06:16
yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SECRET).Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| yeti-platform | yeti | 2.0 ≤ 𝑥 < 2.1.12 |
𝑥
= Vulnerable software versions