CRITICAL🇵🇱 Wersja polska

CVE-2023-27584

CVSS 9.8v3.1pub. 2024-09-19upd. 2024-12-20

Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. Dragonfly uses JWT to verify user. However, the secret key for JWT, "Secret Key", is hard coded, which leads to authentication bypass. An attacker can perform any action as a user with admin privileges. This issue has been addressed in release version 2.0.9. All users are advised to upgrade. There are no known workarounds for this vulnerability.

🤖 AI Analysis
How it works

The Dragonfly system uses JWT tokens to verify user identity. The secret key used to sign and verify these tokens is hard-coded in the application's source code. Since the key is known and immutable, an attacker can independently generate a properly signed JWT token with arbitrary privileges. As a result, the authentication mechanism can be completely bypassed without possessing any credentials.

Impact

A remote unauthenticated attacker can perform arbitrary actions with administrator privileges, leading to complete breach of confidentiality, integrity, and availability of the system.

Mitigation & patch

Dragonfly2 should be immediately updated to version 2.0.9 or later. The manufacturer does not indicate any known workarounds for this vulnerability. Patch available at: https://github.com/dragonflyoss/Dragonfly2/releases/tag/v2.0.9

Who is affected

Dragonfly2 (dragonflyoss/Dragonfly2) — all versions before 2.0.9

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Linuxfoundation Dragonfly

    APP
    Linuxfoundation
    < 2.0.9
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-24124HIGH8.9same product

Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 ...

CVE-2025-59353HIGH7.7same product

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer ...

CVE-2025-59345HIGH7.7same product

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /ap...

CVE-2025-59346MEDIUM5.5same product

Dragonfly is an open source P2P-based file distribution and image acceleration system. Versions prior to 2.1.0...

CVE-2025-59348MEDIUM5.5same product

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the pro...