HMAC Secret Hardcoding Vulnerability in Evershop by NPM
CVE-2023-46943
9.1CRITICAL
What is CVE-2023-46943?
A vulnerability exists in the @evershop/evershop package where the HMAC secret used for generating tokens is hardcoded to 'secret'. This predictable hardcoded value presents a significant security risk, as malicious actors may exploit it to forge valid JSON Web Tokens (JWTs). These tokens could grant unauthorized access to sensitive information and application functionalities, potentially leading to serious breaches. Ensuring the use of strong, non-predictable HMAC secrets is critical to maintaining application integrity and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
