CVE-2024-57432

Source
https://cve.org/CVERecord?id=CVE-2024-57432
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-57432.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-57432
Published
2025-01-31T00:00:00Z
Modified
2026-07-15T01:49:14.424930980Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is explicitly written into the JWT and used for subsequent privilege management, making it is possible to forge the JWT of any user to achieve authentication bypass.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/57xxx/CVE-2024-57432.json"
}
References

Affected packages

Git / github.com/macrozheng/mall-tiny

Affected ranges

Type
GIT
Repo
https://github.com/macrozheng/mall-tiny
Events
Database specific
{
    "source": "CPE_STRING",
    "cpe": "cpe:2.3:a:macrozheng:mall-tiny:1.0.1:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.0.1"
        },
        {
            "last_affected": "1.0.1"
        }
    ]
}

Affected versions

1.*
1.0.1
v1.*
v1.0.0
v1.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-57432.json"