Vulnerabilities
Vulnerable Software
Ymfe:  >> Yapi  >> 1.2.6  Security Vulnerabilities
Weak JSON Web Token (JWT) signing secret generation in YMFE YApi through 1.9.2 allows recreation of other users' JWT tokens. This occurs because Math.random in Node.js is used.
CVSS Score
5.1
EPSS Score
0.001
Published
2021-03-01


Contact Us

Shodan ® - All rights reserved