European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://iuclid6.echa.europa.eu | product |
https://iuclid6.echa.europa.eu/download | product |
https://iuclid6.echa.europa.eu/documents/1387205/1809530/note_v6.27.6.pdf/76545a65-e6be-6486-280a-7d7c3d2ad455?t=1677577170669 | mitigation vendor advisory |