Description
Dromara Sureness before v1.0.8 was discovered to use a hardcoded key.
Remediation
References
https://github.com/dromara/sureness/issues/164
https://github.com/xubowenW/JWTissues/blob/main/sureness%20secure%20issues.md
Related Vulnerabilities
CVE-2020-6422 Vulnerability in maven package org.webjars.npm:electron
CVE-2023-26920 Vulnerability in maven package org.webjars.npm:fast-xml-parser
CVE-2022-39203 Vulnerability in npm package matrix-appservice-irc
CVE-2021-42392 Vulnerability in maven package com.h2database:h2
CVE-2021-27578 Vulnerability in maven package org.apache.zeppelin:zeppelin