Skip to content

Critical security issues: exposed JWT secret and vulnerable MongoDB #2092

@alvaro-salort

Description

@alvaro-salort

This repository another serious security issues:

Hardcoded JWT secret

The file contains a public JWT_SECRET.
Anyone can use this value to forge valid authentication tokens and impersonate users.

Once a JWT secret is committed to a public repo, it must be considered permanently compromised and rotated 🦊

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions