security2 distinct publishers
A manipulated Bearer header escalates privileges in Cleo Harmony through 5.8.1.10
The flaw sits in the JWT refresh token handler, needs nothing more than a rewritten authorization header over plain HTTP, and the fix is a point release to 5.8.1.11 that no change board should need a month to approve.
Reality
- Evidence62
- Adoption32
- Hype gap+18
- Incentives58