RULE(RULE ID:338144)

Rule General Information
Release Date: 2024-06-18
Rule Name: Veeam Recovery Orchestrator Hard-coded JWT Secret Authentication Bypass Vulnerability (CVE-2024-29855)
Severity:
CVE ID:
Rule Protection Details
Description: Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator
Impact: An unauthorized remote attacker can bypass authentication and gain access to the application with specially crafted requests.
Affected OS: Windows, Linux, Others
Reference: https://www.veeam.com/kb4585
Solutions
Refer to the announcement or patch by the vendor: https://www.veeam.com/kb4585