翻译: Peppermint 0.5.5 及之前版本在 中硬编码了 JWT 签名密钥,使得未认证的 attackers(攻击者)能够伪造任意账户的会话令牌。攻击者可以利用该公开密钥为任意用户 ID 生成有效的令牌,从而无需凭证即可访问受保护的端点。 术语说明与润色: "unauthenticated attackers" 译为“未认证的 attackers”或更自然地说“未认证的攻击者”。 "mint valid tokens" 中的 "mint" 在密码学语境下通常译为“签发”或“铸造”,这里用“生成”或“签发”
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Peppermint-Lab | peppermint | ≤ 0.5.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Peppermint-Lab | peppermint | 0 ~ 0.5.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet