A vulnerability has been found in youth-is-as-pale-as-poetry e-learning 1.0. Impacted is the function encryptSecret of the file e-learning-master\exam-api\src\main\java\com\yf\exam\ability\shiro\jwt\JwtUtils.java of the component JWT Token Handler. The manipulation leads to insufficiently random values. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used.
References
Configurations
No configuration.
History
18 Sep 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-18 15:15
Updated : 2025-09-19 16:00
NVD link : CVE-2025-10671
Mitre link : CVE-2025-10671
CVE.ORG link : CVE-2025-10671
JSON object : View
Products Affected
No product.