Key Management Errors
CVE-2025-13877
Summary
A vulnerability was detected in nocobase through 1.9.0-beta.17 , 1.9.1 through 1.9.21 and 2.0.0-alpha1 through 2.0.0-alpha.51. The affected file "nocobase\packages\core\auth\src\base\jwt-service.ts" of the component JWT Service. The manipulation of the argument "API_KEY" results in use of hard-coded cryptographic key . The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- HIGH
- NETWORK
- LOW
- UNCHANGED
- NONE
- NONE
- LOW
- LOW
CWE-320 - Key Management Errors
Weaknesses in this category are related to errors in the management of cryptographic keys.
References
Advisory Timeline
- Published