Database/Control plane, storage & DevOps

CyberPower PowerPanel business application - JWT signing key: The JWT signing key is hardcoded in the application, so
CVSS 9.8CVE-2024-33625Control plane, storage & DevOpscurated
Impact
The JWT signing key is hardcoded in the application, so an attacker forges any token they like and becomes any user. Same shape as the hardcoded credentials: a secret that is not secret and cannot be rotated by the operator.
Who can reach it
Unauthenticated, remote. Requires only the shipped software to extract the key.
What to do
Vendor upgrade. Nothing an operator can configure fixes a hardcoded signing key. Isolate the host until patched, and treat any PowerPanel instance that was internet-reachable as compromised.
References
Related entries
- CyberPower PowerPanel business application - hardcoded authentication credentials: A hardcoded credential set compiledCVE-2024-34025 · CyberPower PowerPanel business application - hardcoded authentication credentialsCritical
- Volcano (v1.8.2 and earlier, service account token permissions): Volcano 1.8.2 ships over-permissive settings that letCVE-2024-36533 · Volcano (v1.8.2 and earlier, service account token permissions)Critical
- VMware vCenter Server (DCERPC heap overflow): A heap overflow in the DCERPC implementation lets an unauthenticatedCVE-2024-37080 · VMware vCenter Server (DCERPC heap overflow)Critical
- Terraform (go-getter): Argument injection when go-getter shells out to Git for remote branch discoveryCVE-2024-3817 · Terraform (go-getter)Critical
- Veeam Backup & Replication: Deserialization of untrusted dataCVE-2024-40711 · Veeam Backup & ReplicationCritical
- Fluent Bit: "Linguistic Lumberjack" - memory corruption parsing trace requests in the embedded HTTP serverCVE-2024-4323 · Fluent BitCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.