An issue was discovered in Object First 1.0.7.712. The...
Critical severity
Unreviewed
Published
Nov 7, 2022
to the GitHub Advisory Database
•
Updated Jun 24, 2025
Description
Published by the National Vulnerability Database
Nov 7, 2022
Published to the GitHub Advisory Database
Nov 7, 2022
Last updated
Jun 24, 2025
An issue was discovered in Object First 1.0.7.712. The authorization service has a flow that allows getting access to the Web UI without knowing credentials. For signing, the JWT token uses a secret key that is generated through a function that doesn't produce cryptographically strong sequences. An attacker can predict these sequences and generate a JWT token. As a result, an attacker can get access to the Web UI. This is fixed in 1.0.13.1611.
References