CVE-2021-27884

Severity CVSS v4.0:
Pending analysis
Type:
CWE-330 Use of Insufficiently Random Value
Publication date:
01/03/2021
Last modified:
08/03/2021

Description

Weak JSON Web Token (JWT) signing secret generation in YMFE YApi through 1.9.2 allows recreation of other users' JWT tokens. This occurs because Math.random in Node.js is used.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ymfe:yapi:*:*:*:*:*:*:*:* 1.9.2 (including)