CVE Vulnerabilities

CVE-2025-30064

Improper Verification of Cryptographic Signature

Published: Aug 27, 2025 | Modified: Aug 29, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not verify which signing algorithm was used. As a result, an attacker can use the ex:action parameter in the VerifyUserByThrustedService function to generate a session for any user.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

References