Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-17816 | The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can generate and use a verifiable JWT token to access protected ArchiverSpaApi URL endpoints. |
| Link | Providers |
|---|---|
| https://www.tenable.com/security/research/tra-2025-17 |
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 11 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Jun 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can generate and use a verifiable JWT token to access protected ArchiverSpaApi URL endpoints. | |
| Title | Hard-coded ArchiverSpaApi JWT Signing Key | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2025-06-11T14:03:33.168Z
Reserved: 2025-04-15T21:07:39.881Z
Link: CVE-2025-35940
Updated: 2025-06-11T14:03:28.655Z
Status : Deferred
Published: 2025-06-10T21:15:22.210
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-35940
No data.
OpenCVE Enrichment
No data.
EUVD