CVE-2013-7379: Ucdok Tomato

Medium severity, CVSS 6.8. EPSS: 2.5% chance of exploitation in the next 30 days.

The admin API in the tomato module before 0.0.6 for Node.js does not properly check the access key when it is set to a string, which allows remote attackers to bypass authentication via a string in the access-key header that partially matches config.master.api.access_key.

Affected products

  • Ucdok Tomato: up to and including 0.0.5

Published 2014-05-16. Last modified 2026-06-17.