Use of a hard-coded cryptographic key in Pancake versions < 4.13.29 allows an attacker to forge session cookies, which may lead to remote privilege escalation.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://www.pancakeapp.com/blog/entry/pancake-4.13.29-released | release notes vendor advisory |
https://www.vaadata.com/blog/hardcoded-secret-leads-to-account-takeover/ | third party advisory |