Dragonfly Authentication Bypass Vulnerability
CVE-2023-27584
What is CVE-2023-27584?
Dragonfly, an open-source P2P-based file distribution and image acceleration platform hosted by the Cloud Native Computing Foundation, suffers from a significant vulnerability related to its JWT authentication mechanism. The secret key used for JWT verification is hard-coded as 'Secret Key', allowing an attacker to bypass authentication completely. This flaw enables malicious actors to execute actions with admin-level privileges, posing a serious risk to the security and integrity of the affected system. Users are strongly encouraged to upgrade to version 2.0.9 to mitigate this vulnerability, as there are no viable workarounds available.
Affected Version(s)
Dragonfly2 < 2.0.9
References
EPSS Score
33% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
