Vendor
An unpatched vulnerability in Duplicati 2.2.0.3 allows authenticated attackers to bypass security guards and extract JWT signing keys to forge administrative tokens.