Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33591
HistoryJan 11, 2022 - 11:39 a.m.

Insecure Session Management

2022-01-1111:39:56
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
insecure session
jwt secret key
unauthorized access

EPSS

0.002

Percentile

58.3%

github.com/sipcapture/homer-app uses insecure session management. The vulnerability exists as the JWT secret key is hard coded in constants.go file, allowing a user to gain unauthorized access to the application if the default secret key is not changed.

EPSS

0.002

Percentile

58.3%