CVE-2025-13948

A vulnerability was determined in opsre go-ldap-admin up to 20251011. This issue affects some unknown processing of the file docs/docker-compose/docker-compose.yaml of the component JWT Handler. Executing manipulation of the argument secret key can lead to use of hard-coded cryptographic key . The attack can be launched remotely. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been publicly disclosed and may be utilized.
Configurations

No configuration.

History

03 Dec 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-03 15:15

Updated : 2025-12-03 15:15


NVD link : CVE-2025-13948

Mitre link : CVE-2025-13948

CVE.ORG link : CVE-2025-13948


JSON object : View

Products Affected

No product.

CWE
CWE-320

Key Management Errors

CWE-321

Use of Hard-coded Cryptographic Key