PT-2024-13391 · Npm · @Evershop/Evershop

CVE-2023-46943

·

Published

2024-01-12

·

Updated

2024-08-30

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions @evershop/evershop versions prior to 1.0.0-rc.8
Description An issue was discovered in NPM's package @evershop/evershop where the HMAC secret used for generating tokens is hardcoded as "secret". This poses a risk because attackers can use the predictable secret to create valid JSON Web Tokens (JWTs), allowing them access to important information and actions within the application.
Recommendations For versions prior to 1.0.0-rc.8, update to version 1.0.0-rc.8 or later to resolve the issue. As a temporary workaround, consider regenerating the HMAC secret with a secure, randomly generated value to prevent attackers from creating valid JSON Web Tokens (JWTs).

Fix

Using Hardcoded Credentials

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-46943
GHSA-32R3-57HP-CGFW

Affected Products

@Evershop/Evershop