CVE-2023-53951
CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key implementation. Attackers can leverage the exposed JWT token to authenticate and gain unauthorized access with administrative permissions.
Metadata
Severity & Metrics
9.8
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Gauzy | ever gauzy | — | 0.281.9 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-347 | cna | Improper Verification of Cryptographic Signature |
CVSS scores (2)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.8 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 9.3 | CRITICAL | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
References (3)
- ExploitDB-51354 https://www.exploit-db.com/exploits/51354
- Official Product Homepage https://github.com/ever-co/ever-gauzy
- VulnCheck Advisory: Ever Gauzy v0.281.9 JWT Authentication Weakness via HMAC Secret https://www.vulncheck.com/advisories/ever-gauzy-jwt-authentication-weakness-via-hmac-secret