Vulnerabilities (CVE)

Filtered by vendor Prolion Subscribe
Filtered by product Cryptospike
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-36649 1 Prolion 1 Cryptospike 2023-12-14 N/A 9.1 CRITICAL
Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management and the REST API by reading JWT tokens from logs (as a Granafa authenticated user) or from the Loki REST API without authentication.
CVE-2023-36655 1 Prolion 1 Cryptospike 2023-12-12 N/A 9.8 CRITICAL
The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login and obtain an authentication token by specifying a username with different uppercase/lowercase character combination.