Casdoor 4.4.0 及更早版本在 和 端点未能正确遮蔽实例级别的内置证书私钥,导致组织管理员能够获取该私钥。攻击者可利用此泄露的私钥为任意组织中的任何用户(包括全局管理员)伪造 JWT 令牌。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet