{"id":"GHSA-xr8c-mq5x-5f56","summary":"Dromara Lamp-Cloud Use of Hard-coded Cryptographic Key","details":"Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability allows attackers to authenticate to the application via a crafted JWT token.","aliases":["CVE-2023-31579"],"modified":"2024-02-16T08:13:19.585649Z","published":"2023-11-03T00:30:26Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-11-03T19:23:51Z","nvd_published_at":"2023-11-02T22:15:08Z","cwe_ids":["CWE-798"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-31579"},{"type":"WEB","url":"https://github.com/dromara/lamp-cloud/issues/183"},{"type":"WEB","url":"https://github.com/dromara/lamp-cloud/commit/31f79b122d85ed1b4f354673212692aa8205437a"},{"type":"WEB","url":"https://github.com/xubowenW/JWTissues/blob/main/lamp%20issue.md"}],"affected":[{"package":{"name":"top.tangyh.basic:lamp-core","ecosystem":"Maven","purl":"pkg:maven/top.tangyh.basic/lamp-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.8.1"}]}],"versions":["3.4.0","3.5.0","3.5.1","3.5.3","3.5.5","3.5.7","3.5.8","3.6.0","3.6.2","3.7.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-xr8c-mq5x-5f56/GHSA-xr8c-mq5x-5f56.json"}},{"package":{"name":"top.tangyh.basic:lamp-util","ecosystem":"Maven","purl":"pkg:maven/top.tangyh.basic/lamp-util"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.8.1"}]}],"versions":["3.4.0","3.5.0","3.5.1","3.5.3","3.5.7","3.5.8","3.6.0","3.6.2","3.7.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-xr8c-mq5x-5f56/GHSA-xr8c-mq5x-5f56.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}