IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 28 Apr 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thecosy
Thecosy icecms |
|
| CPEs | cpe:2.3:a:thecosy:icecms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Thecosy
Thecosy icecms |
Tue, 24 Sep 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Icecms Project
Icecms Project icecms |
|
| Weaknesses | CWE-321 | |
| CPEs | cpe:2.3:a:icecms_project:icecms:3.4.7:*:*:*:*:*:*:* | |
| Vendors & Products |
Icecms Project
Icecms Project icecms |
|
| Metrics |
cvssV3_1
|
Tue, 24 Sep 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-09-24T00:00:00
Updated: 2024-09-24T20:35:27.218Z
Reserved: 2024-09-11T00:00:00
Link: CVE-2024-46612
Updated: 2024-09-24T20:35:19.887Z
Status : Analyzed
Published: 2024-09-25T01:15:44.550
Modified: 2025-04-28T18:15:57.590
Link: CVE-2024-46612
No data.