{"id":"GHSA-3j2f-58rq-g6p7","summary":"Sureness uses hardcoded key","details":"Dromara Sureness before v1.0.8 was discovered to use a hardcoded key.","aliases":["CVE-2023-31581"],"modified":"2023-11-10T05:54:55.732080Z","published":"2023-10-25T18:32:21Z","database_specific":{"github_reviewed_at":"2023-10-27T19:12:28Z","nvd_published_at":"2023-10-25T18:17:27Z","cwe_ids":["CWE-798"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-31581"},{"type":"WEB","url":"https://github.com/dromara/sureness/issues/164"},{"type":"WEB","url":"https://github.com/dromara/sureness/commit/12987a72cbf1eabbca1e308ed1fe9445958aeca7"},{"type":"PACKAGE","url":"https://github.com/dromara/sureness"},{"type":"WEB","url":"https://github.com/xubowenW/JWTissues/blob/main/sureness%20secure%20issues.md"}],"affected":[{"package":{"name":"com.usthe.sureness:sureness-core","ecosystem":"Maven","purl":"pkg:maven/com.usthe.sureness/sureness-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.8"}]}],"versions":["0.0.1","0.0.1.1","0.0.2","0.0.2.1","0.0.2.2","0.0.2.3","0.0.2.4","0.0.2.5","0.0.2.6","0.0.2.7","0.0.2.8","0.1","0.2","0.3","0.4","0.4.1","0.4.2","0.4.3","0.4.4","0.4.5","0.4.6","1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.4-beta","1.0.4-beta.1","1.0.4-beta.2","1.0.5","1.0.6","1.0.6.beta1","1.0.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-3j2f-58rq-g6p7/GHSA-3j2f-58rq-g6p7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}