Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse the token when a session is active. The JWT token does not contain an expiration timestamp.

CVSS 1 Total

ScoreSeverityVersionVector String
4.2MEDIUM3.1CVSS:3.1/AC:H/AV:N/A:N/C:L/I:L/PR:N/S:U/UI:R

Updated:

This container includes required additional information provided by the CVE Program for this vulnerability.