
CVE-2024-46508 yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SEC… https://www.cve.org/CVERecord?id=CVE-2024-46508
Post summary
CVE-2024-46508 is a disclosed vulnerability in Yeti Platform versions before 2.1.12 that allows attackers to forge valid JWT tokens if the secret key has not been changed.
