Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability allows attackers to authenticate to the application via a crafted JWT token.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Dromara Lamp-Cloud 安全漏洞
Vulnerability Description
Dromara Lamp-Cloud是基于Jdk11 + SpringCloud + SpringBoot 开发的微服务中后台快速开发平台,专注于多租户(SaaS架构)解决方案,亦可作为普通项目(非SaaS架构)的基础开发框架使用,目前已实现插拔式数据库隔离、SCHEMA隔离、字段隔离等租户隔离方案。 Dromara Lamp-Cloud v3.8.1 之前版本存在安全漏洞,该漏洞源于在创建和验证 Json Web Token 时被发现使用硬编码的加密密钥,攻击者利用该漏洞可以通过精心设计的 JWT 令牌
CVSS Information
N/A
Vulnerability Type
N/A