{"id":"GHSA-q72p-4w56-hx7h","summary":"Hardcoded JWT Token in Lin CMS Spring Boot","details":"An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application.","aliases":["CVE-2022-32430"],"modified":"2024-02-16T08:06:32.211031Z","published":"2022-07-22T00:00:37Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-07-11T00:16:48Z","nvd_published_at":"2022-07-21T16:15:00Z","cwe_ids":["CWE-668"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-32430"},{"type":"PACKAGE","url":"https://github.com/TaleLin/lin-cms-spring-boot"},{"type":"WEB","url":"https://github.com/TaleLin/lin-cms-spring-boot/blob/3fc25bd8c10c73db2e7230809b322127eac554e3/src/main/resources/application.yml#L43"},{"type":"WEB","url":"https://web.archive.org/web/20220721190946/https://www.mesec.cn/archives/277"}],"affected":[{"package":{"name":"io.github.talelin:lin-cms-core","ecosystem":"Maven","purl":"pkg:maven/io.github.talelin/lin-cms-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.2.1"}]}],"versions":["0.0.1-RC1","0.0.1-RC2","0.0.1-RC3","0.0.1-RC4","0.0.1-RC5","0.0.1-RC6","0.1.0-RELEASE","0.1.1-RC1","0.1.1-RC2","0.1.1-RC3","0.2.0-RC1","0.2.0-RC2","0.2.0-RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-q72p-4w56-hx7h/GHSA-q72p-4w56-hx7h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}