CVE Details
Basic Information
| Title |
CVE-2025-47945 Donetick Has Weak Default JWT Secret |
| Type |
cve |
| Published |
2025-05-17T18:36:11 |
| Last Seen |
2025-05-17T19:02:35 |
CVSS Information
| Base Score |
9.1 (CRITICAL) |
| Attack Vector |
NETWORK |
| Attack Complexity |
LOW |
| Privileges Required |
NONE |
| User Interaction |
NONE |
| Scope |
UNCHANGED |
| Confidentiality Impact |
HIGH |
| Integrity Impact |
HIGH |
| Availability Impact |
NONE |
AI Analysis
| AI Description |
|
| AI Severity |
|
| Vendor |
|
| Product |
|
| Affected Version |
|
Additional Information
| CVE List |
CVE-2025-47945 |
| CWE List |
CWE-1188, CWE-453 |
| Bulletin Family |
cve |
Description
Donetick an open-source app for managing tasks and chores. Prior to version 0.1.44, the application uses JSON Web Tokens (JWT) for authentication, but the signing secret has a weak default value. While the responsibility is…
CVSS Score Summary
Base Score: %!f(string=#) (CRITICAL)
View Full CVE Details