← Vulnerability feed

Vulnerability record · CVE-2023-27584 · published 19 September 2024

CVE-2023-27584: Linuxfoundation dragonfly hard-coded credentials vulnerability

Linuxfoundation · Dragonfly

Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. Dragonfly uses JWT to verify user. However, the secret key for JWT, "Secret Key", is hard coded, which leads to authentication bypass. An attacker can perform any action as a user with admin privileges. This issue has been addressed in release version 2.0.9. All users are advised to upgrade. There are no known workarounds for this vulnerability.

9.8 CVSS 3.1 Critical EPSS 34% · top 1.7% CWE-321 · CWE-321CWE-798 · Hard-coded credentials
9.8CVSS 3.1 base score
34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. Dragonfly uses JWT to verify user. However, the secret key for JWT, "Secret Key", is hard coded, which leads to authentication bypass. An attacker can perform any action as a user with admin privileges. This issue has been addressed in release version 2.0.9. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-27584 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.9CVE-2026-24124Linuxfoundation dragonfly missing authentication for critical function vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/…EPSS 0.79%7.7CVE-2025-59353Linuxfoundation dragonfly improper certificate validation vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain a valid TLS certificate for …EPSS 0.23%7.7CVE-2025-59345Linuxfoundation dragonfly missing authentication for critical function vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /api/v1/jobs and /preheats endpoints in Ma…EPSS 0.38%6.9CVE-2025-59352Linuxfoundation dragonfly path traversal vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the gRPC API and HTTP APIs allow peers to send…EPSS 0.73%5.5CVE-2025-59354Linuxfoundation dragonfly vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the DragonFly2 uses a variety of hash function…EPSS 0.16%5.5CVE-2025-59410Linuxfoundation dragonfly missing encryption vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the code in the scheduler for downloading a ti…EPSS 0.14%5.5CVE-2025-59348Linuxfoundation dragonfly vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the processPieceFromSource method does not upd…EPSS 0.36%5.5CVE-2025-59346Linuxfoundation dragonfly server-side request forgery (ssrf) vulnerabilityDragonfly is an open source P2P-based file distribution and image acceleration system. Versions prior to 2.1.0 contain a server-side request forgery …EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2023-27584), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.