CWE-1270

Total CVEs
4
Vulnerabilities
Avg CVSS v3
6.5
Medium
Latest CVE
2023
Most Recent

Severity Distribution

Critical 3
75%
High 0
0%
Medium 1
25%
Low 0
0%

External References

All CVEs (4)

Page 1 of 1
CVSS:9.8(Critical)

Generation of Incorrect Security Tokens vulnerability in CBOT Chatbot allows Token Impersonation, Privilege Abuse.This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.

CVSS:5.5(Medium)

A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead ...

CVSS:4.3(Medium)

Jenkins Report Portal Plugin 0.5 and earlier does not mask ReportPortal access tokens displayed on the configuration form, increasing the potential for attackers to observe and capture them.

A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead ...