Dispatch writes JWT tokens in error message
CVE-2023-40171
What is CVE-2023-40171?
The Dispatch management tool, developed by Netflix, has a vulnerability where the JWT Secret Key utilized for signing tokens is inadvertently revealed in error messages during token decoding failures by the Dispatch Plugin - Basic Authentication Provider. This exposure could potentially allow unauthorized users to craft their own JWTs and gain access to compromised accounts within an affected instance. Affected users are strongly encouraged to rotate their JWT Secret Key stored in the DISPATCH_JWT_SECRET environment variable in their .env file. The vulnerability has been resolved in the release dated August 17, 2023, and users should promptly upgrade to the latest version to ensure their instances remain secure. There are currently no workarounds available for this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
dispatch < 20230817
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
