Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Note Mark: JWT Secret Weakness allows Full Account Takeover via token forgery
Vulnerability Description
Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JWT_SECRET configuration value. The application accepts any base64-decodable secret regardless of size, including secrets as short as 1 byte. This vulnerability is fixed in 0.19.4.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Vulnerability Type
不充分的加密强度
Vulnerability Title
Note Mark 加密问题漏洞
Vulnerability Description
Note Mark是Leo Spratt个人开发者的一个基于网络的Markdown笔记应用程序。 Note Mark 0.19.4之前版本存在加密问题漏洞,该漏洞源于JWT_SECRET配置值未强制最小长度或熵,可能导致弱密钥攻击。
CVSS Information
N/A
Vulnerability Type
N/A