漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Note Mark: JWT Secret Weakness allows Full Account Takeover via token forgery
Vulnerability Description
Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JWT_SECRET configuration value. The application accepts any base64-decodable secret regardless of size, including secrets as short as 1 byte. This vulnerability is fixed in 0.19.4.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Vulnerability Type
不充分的加密强度
Vulnerability Title
Note Mark 加密问题漏洞
Vulnerability Description
Note Mark是Leo Spratt个人开发者的一个基于网络的Markdown笔记应用程序。 Note Mark 0.19.4之前版本存在加密问题漏洞,该漏洞源于JWT_SECRET配置值未强制最小长度或熵,可能导致弱密钥攻击。
CVSS Information
N/A
Vulnerability Type
N/A