CVE-2023-36649

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
12/12/2023
Last modified:
14/12/2023

Description

Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management and the REST API by reading JWT tokens from logs (as a Granafa authenticated user) or from the Loki REST API without authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:prolion:cryptospike:3.0.15:p2:*:*:*:*:*:*


References to Advisories, Solutions, and Tools