security1 distinct publisher
A manipulated Bearer header escalates privileges in Cleo Harmony through 5.8.1.10
The flaw sits in the JWT refresh token handler, needs nothing more than a rewritten authorization header over plain HTTP, and the fix is a point release to 5.8.1.11 that no change board should need a month to approve.
Publishers:thecyberexpress.com
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+22
- Incentives55