CVE-2024-34354 - CVE House
Back to Database
Status published Medium CVE-2024-34354

CMSaasStarter: JWT Token Not Verified on Server Session

Vulnerability Description

CMSaaSStarter is a SaaS template/boilerplate built with SvelteKit, Tailwind, and Supabase. Any forks of the CMSaaSStarter template before commit 7904d416d2c72ec75f42fbf51e9e64fa74062ee6 are impacted. The issue is the user JWT Token is not verified on server session. You should take the patch 7904d416d2c72ec75f42fbf51e9e64fa74062ee6 into your fork.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-34354

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

CriticalMoments

View all reports →

Affected Software

CMSaasStarter
Vulnerable Versions:
< 7904d416d2c72ec75f42fbf51e9e64fa74062ee6

Timeline

Official Publish: May 9th, 2024
Last Modified: August 2nd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Weaknesses (CWE)