Vulnerabilities > Prolion > Cryptospike > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-12-12 CVE-2023-36649 Information Exposure Through Log Files vulnerability in Prolion Cryptospike 3.0.15
Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management and the REST API by reading JWT tokens from logs (as a Granafa authenticated user) or from the Loki REST API without authentication.
network
low complexity
prolion CWE-532
critical
9.1
2023-12-06 CVE-2023-36655 Improper Authentication vulnerability in Prolion Cryptospike 3.0.15
The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login and obtain an authentication token by specifying a username with different uppercase/lowercase character combination.
network
low complexity
prolion CWE-287
critical
9.8