Metrics
Affected Vendors & Products
Mon, 04 May 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 04 May 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yunaiv
Yunaiv yudao-cloud |
|
| Vendors & Products |
Yunaiv
Yunaiv yudao-cloud |
Sun, 03 May 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in YunaiV yudao-cloud up to 3.8.0. This affects the function doFilterInternal of the file JwtAuthenticationTokenFilter.java of the component Ruoyi-Vue-Pro. Performing a manipulation of the argument mock-token results in improper authentication. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | YunaiV yudao-cloud Ruoyi-Vue-Pro JwtAuthenticationTokenFilter.java doFilterInternal improper authentication | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-05-03T23:15:17.816Z
Updated: 2026-05-04T13:07:34.227Z
Reserved: 2026-05-03T07:38:31.974Z
Link: CVE-2026-7710
Updated: 2026-05-04T13:07:18.318Z
Status : Deferred
Published: 2026-05-04T00:16:39.633
Modified: 2026-05-05T19:11:29.130
Link: CVE-2026-7710
No data.
ReportizFlow