GHSA-8v5f-hp78-jgxq

Suggest an improvement
Source
https://github.com/advisories/GHSA-8v5f-hp78-jgxq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-8v5f-hp78-jgxq/GHSA-8v5f-hp78-jgxq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-8v5f-hp78-jgxq
Downstream
Published
2019-06-06T15:30:33Z
Modified
2020-08-31T18:37:26Z
Summary
Signature Verification Bypass in jwt-simple
Details

Versions of jwt-simple prior to 0.5.3 are vulnerable to Signature Verification Bypass. If no algorithm is specified in the decode() function, the packages uses the algorithm in the JWT to decode tokens. This allows an attacker to create a HS256 (symmetric algorithm) JWT with the server's public key as secret, and the package will verify it as HS256 instead of RS256 (asymmetric algorithm).

Recommendation

Upgrade to version 0.5.3 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-347"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2019-06-06T09:42:36Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / jwt-simple

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.5.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-8v5f-hp78-jgxq/GHSA-8v5f-hp78-jgxq.json"