CVE-2024-46508 PUBLISHED

Assigner: mitre
Reserved: 11.09.2024 Published: 08.05.2026 Updated: 08.05.2026

yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SECRET).

Product Status

Vendor n/a
Product n/a
Versions
  • Version n/a is affected

References

Problem Types

  • n/a text