Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 1 min 121 bronnen 2 kritiek 14 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2025-10671

LOW · 3.7 CVSS Gepubliceerd: CWE-310

Beschrijving NL

Er is een kwetsbaarheid gevonden in youth-is-as-pale-as-poetry e-learning 1.0. Beïnvloed is de functie encryptSecret van het bestand e-learning-masterexam-apisrcmainjavacomyfexamabilityshirojwtJwtUtils.java van de component JWT Token Handler. De manipulatie leidt tot onvoldoende willekeurige waarden. De aanval kan op afstand worden gestart. De complexiteit van een aanval is vrij hoog. De exploiteerbaarheid wordt als moeilijk beschouwd. De exploit is openbaar gemaakt en kan worden gebruikt.

Origineel (Engels) tonen

A vulnerability has been found in youth-is-as-pale-as-poetry e-learning 1.0. Impacted is the function encryptSecret of the file e-learning-masterexam-apisrcmainjavacomyfexamabilityshirojwtJwtUtils.java of the component JWT Token Handler. The manipulation leads to insufficiently random values. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used.

References