id: PYSEC-2021-342 details: A Hardcoded JWT Secret Key in metadata.py in AdaptiveScale LXDUI through 2.1.3 allows attackers to gain admin access to the host system. affected: - package: name: lxdui ecosystem: PyPI purl: pkg:pypi/lxdui ranges: - type: ECOSYSTEM events: - introduced: "0" versions: - 1.0.1 references: - type: WEB url: https://github.com/AdaptiveScale/lxdui/pull/353 - type: ADVISORY url: https://github.com/advisories/GHSA-p4xh-4869-8vrg aliases: - CVE-2021-40494 - GHSA-p4xh-4869-8vrg modified: "2021-09-26T23:32:34.569818Z" published: "2021-09-03T02:15:00Z"