Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse the token when a session is active. The JWT token does not contain an expiration timestamp.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Vulnerability Type
N/A
Vulnerability Title
Tangro Business Workflow 安全漏洞
Vulnerability Description
Tangro Business Workflow是德国Tangro公司的一款可将SAP文档内容的内部控制以及批准流程进行可视化绘制的软件。 tangro Business Workflow before 1.18.1 存在安全漏洞,该漏洞源于每次登录都会生成相同的JWT令牌,它允许攻击者可利用该漏洞在会话激活时重用令牌。JWT令牌不包含到期时间戳。
CVSS Information
N/A
Vulnerability Type
N/A