Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signature when verifying host tokens. An attacker can forge a JWT signed with any arbitrary key and use it to impersonate any host in the network, gaining access to sensitive information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:NNetmaker
APPNetmaker< 1.5.0
Related vulnerabilities
Hardkodowany klucz kryptograficzny w Netmaker — nieautoryzowany dostęp
Netmaker makes networks with WireGuard. Prior to version 1.2.0, the /api/server/shutdown endpoint allows termi...
Netmaker makes networks with WireGuard. Prior to versions 0.17.1 and 0.18.6, hardcoded DNS key usage has been ...
Netmaker makes networks with WireGuard. An Insecure Direct Object Reference (IDOR) vulnerability was found in ...
Netmaker makes networks with WireGuard. A Mass assignment vulnerability was found in versions prior to 0.17.1 ...