CVE-2025-40646

Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information about customers by intercepting HTTP requests and searching for the JWT containing sensitive user information in the JWT payload.
CVSS

No CVSS.

Configurations

No configuration.

History

02 Oct 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-02 10:15

Updated : 2025-10-02 19:11


NVD link : CVE-2025-40646

Mitre link : CVE-2025-40646

CVE.ORG link : CVE-2025-40646


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor