blob: 732026466463106202ecb433f5d7a4bd02a85b07 [file] [log] [blame]
id: GO-2023-1931
modules:
- module: github.com/IceWhaleTech/CasaOS
versions:
- fixed: 0.4.4
vulnerable_at: 0.4.4-alpha9
summary: CasaOS contains weak JWT secrets in github.com/IceWhaleTech/CasaOS
cves:
- CVE-2023-37266
ghsas:
- GHSA-m5q5-8mfw-p2hr
references:
- advisory: https://github.com/IceWhaleTech/CasaOS/security/advisories/GHSA-m5q5-8mfw-p2hr
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-37266
- fix: https://github.com/IceWhaleTech/CasaOS/commit/705bf1facbffd2ca40b159b0303132b6fdf657ad
- web: https://www.sonarsource.com/blog/security-vulnerabilities-in-casaos
source:
id: GHSA-m5q5-8mfw-p2hr
created: 2024-08-20T11:52:31.059067-04:00
review_status: UNREVIEWED
unexcluded: EFFECTIVELY_PRIVATE