GHSA-3j2f-58rq-g6p7

Suggest an improvement
Source
https://github.com/advisories/GHSA-3j2f-58rq-g6p7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-3j2f-58rq-g6p7/GHSA-3j2f-58rq-g6p7.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-3j2f-58rq-g6p7
Aliases
Published
2023-10-25T18:32:21Z
Modified
2023-11-10T05:54:55.732080Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Sureness uses hardcoded key
Details

Dromara Sureness before v1.0.8 was discovered to use a hardcoded key.

Database specific
{
    "nvd_published_at": "2023-10-25T18:17:27Z",
    "cwe_ids": [
        "CWE-798"
    ],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2023-10-27T19:12:28Z"
}
References

Affected packages

Maven / com.usthe.sureness:sureness-core

Package

Name
com.usthe.sureness:sureness-core
View open source insights on deps.dev
Purl
pkg:maven/com.usthe.sureness/sureness-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.8

Affected versions

0.*

0.0.1
0.0.1.1
0.0.2
0.0.2.1
0.0.2.2
0.0.2.3
0.0.2.4
0.0.2.5
0.0.2.6
0.0.2.7
0.0.2.8
0.1
0.2
0.3
0.4
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6

1.*

1.0.0
1.0.1
1.0.2
1.0.3
1.0.4-beta
1.0.4-beta.1
1.0.4-beta.2
1.0.4
1.0.5
1.0.6.beta1
1.0.6
1.0.7