CVE-2023-46943 is a critical vulnerability affecting NPM's @evershop/evershop package prior to version 1.0.0-rc.8. The issue stems from a hardcoded HMAC secret ("secret") used for generating JSON Web Tokens (JWTs). This weakness allows attackers to forge valid JWTs, potentially leading to unauthorized access to sensitive information and application functions. With a CVSS score of 9.1 (CRITICAL), this vulnerability is easily exploitable over the network with low attack complexity, posing a significant risk of high confidentiality and integrity impacts. There is no user interaction required for a successful exploit. Currently, there is no evidence of active exploitation, nor are there any public exploit modules or proof-of-concept code available. Community discussion and media coverage for this CVE are minimal, which is typical for a large percentage of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0CPE matchmatch criteria | cpe:2.3:a:evershop:evershop:1.0.0:beta:*:*:*:node.js:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:evershop:evershop:1.0.0:beta1:*:*:*:node.js:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:evershop:evershop:1.0.0:beta2:*:*:*:node.js:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:evershop:evershop:1.0.0:beta3:*:*:*:node.js:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:evershop:evershop:1.0.0:beta4:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.