{ "id": "CVE-2024-48952", "sourceIdentifier": "cve@mitre.org", "published": "2024-11-07T17:15:08.510", "lastModified": "2024-11-08T19:01:03.880", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability enables attackers to create custom JWT secret keys for unauthorized access to these endpoints." }, { "lang": "es", "value": "Se descubri\u00f3 un problema en Logpoint antes de la versi\u00f3n 7.5.0. SOAR usa una clave secreta JWT est\u00e1tica para generar tokens que permiten el acceso a los endpoints de la API de SOAR sin autenticaci\u00f3n. Esta vulnerabilidad de clave est\u00e1tica permite a los atacantes crear claves secretas JWT personalizadas para el acceso no autorizado a estos endpoints." } ], "metrics": { "cvssMetricV31": [ { "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L", "baseScore": 6.4, "baseSeverity": "MEDIUM", "attackVector": "ADJACENT_NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "LOW", "availabilityImpact": "LOW" }, "exploitabilityScore": 1.6, "impactScore": 4.7 } ] }, "weaknesses": [ { "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-306" } ] } ], "references": [ { "url": "https://docs.logpoint.com/docs/whats-new-in-logpoint/en/latest/", "source": "cve@mitre.org" }, { "url": "https://servicedesk.logpoint.com/hc/en-us/articles/21968950913693-Static-JWT-Key-enables-unauthorized-API-access", "source": "cve@mitre.org" }, { "url": "https://servicedesk.logpoint.com/hc/en-us/sections/7201103730845-Product-Security", "source": "cve@mitre.org" } ] }