Home

Description

The Litmus platform uses JWT for authentication and authorization, but the secret being used for signing the JWT is only 6 bytes long at its core, which makes it extremely easy to crack.

PUBLISHED Reserved 2025-12-08 | Published 2025-12-08 | Updated 2025-12-08 | Assigner JFROG




HIGH: 7.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H

Problem types

CWE-331 Insufficient Entropy

Product status

Default status
unaffected

Any version before 3.23.0
affected

References

research.jfrog.com/...entropy-elevation-jfsa-2025-001648159/ third-party-advisory

github.com/litmuschaos/litmus/pull/5324 patch

cve.org (CVE-2025-14261)

nvd.nist.gov (CVE-2025-14261)

Download JSON