Security Advisory

CVE-2023-33371

9.8
CRITICAL

Vulnerability Description

Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication.
Published Date August 3, 2023
Official Source NIST NVD Advisory