Database/Control plane, storage & DevOps

CyberPower PowerPanel business application - JWT signing key: The JWT signing key is hardcoded in the application, so
CVE-2024-33625Control plane, storage & DevOpscurated
Impact
The JWT signing key is hardcoded in the application, so an attacker forges any token they like and becomes any user. Same shape as the hardcoded credentials: a secret that is not secret and cannot be rotated by the operator.
Who can reach it
Unauthenticated, remote. Requires only the shipped software to extract the key.
What to do
Vendor upgrade. Nothing an operator can configure fixes a hardcoded signing key. Isolate the host until patched, and treat any PowerPanel instance that was internet-reachable as compromised.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.