CVE-2022-25898

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-25898
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-25898.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-25898
Aliases
Related
  • SNYK-JAVA-ORGWEBJARSBOWER-2935898
  • SNYK-JAVA-ORGWEBJARSBOWERGITHUBKJUR-2935897
  • SNYK-JAVA-ORGWEBJARSNPM-2935896
  • SNYK-JS-JSRSASIGN-2869122
Published
2022-07-01T20:15:08Z
Modified
2025-01-15T02:19:12.604802Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The package jsrsasign before 10.5.25 are vulnerable to Improper Verification of Cryptographic Signature when JWS or JWT signature with non Base64URL encoding special characters or number escaped characters may be validated as valid by mistake. Workaround: Validate JWS or JWT signature if it has Base64URL and dot safe string before executing JWS.verify() or JWS.verifyJWT() method.

References

Affected packages

Git / github.com/kjur/jsrsasign

Affected ranges

Type
GIT
Repo
https://github.com/kjur/jsrsasign
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

1.*

1.2.0
1.3.0
1.3.1

10.*

10.0.0
10.0.1
10.0.2
10.0.3
10.0.4
10.0.5
10.1.0
10.1.1
10.1.10
10.1.11
10.1.12
10.1.13
10.1.2
10.1.3
10.1.4
10.1.5
10.1.8
10.1.9
10.2.0
10.3.0
10.3.1
10.3.2
10.4.0
10.4.1
10.5.0
10.5.1
10.5.10
10.5.11
10.5.12
10.5.13
10.5.14
10.5.15
10.5.16
10.5.17
10.5.18
10.5.19
10.5.2
10.5.20
10.5.21
10.5.22
10.5.23
10.5.24
10.5.3
10.5.4
10.5.5
10.5.6
10.5.7
10.5.8
10.5.9

2.*

2.0.0

3.*

3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5

4.*

4.0.0
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.2.0
4.2.1
4.2.2
4.2.3
4.5.0
4.6.0
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.8.2
4.8.3
4.8.5
4.8.6
4.9.0
4.9.1
4.9.2

5.*

5.0.0
5.0.1
5.0.10
5.0.11
5.0.12
5.0.13
5.0.14
5.0.15
5.0.2
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0

6.*

6.0.0
6.0.1
6.1.0
6.1.1
6.1.2
6.1.4
6.2.0
6.2.1
6.2.2
6.2.3

7.*

7.0.0
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.2.0
7.2.1
7.2.2

8.*

8.0.0
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.3
8.0.4
8.0.5
8.0.6
8.0.7
8.0.8
8.0.9

9.*

9.0.0
9.0.1
9.0.2
9.0.3
9.1.0
9.1.1
9.1.2
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9