GHSA-r2vw-jgq9-jqx2

Suggest an improvement
Source
https://github.com/advisories/GHSA-r2vw-jgq9-jqx2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-r2vw-jgq9-jqx2/GHSA-r2vw-jgq9-jqx2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-r2vw-jgq9-jqx2
Published
2020-09-03T15:54:11Z
Modified
2020-08-31T19:02:48Z
Summary
Improper Authorization in @sap-cloud-sdk/core
Details

Affected versions of @sap-cloud-sdk/core do not properly validate JWTs. The verifyJwt() function does not properly validate the URL from where the public verification key for the JWT can be downloaded. Any URL was trusted which makes it possible to provide a URL belonging to a manipulated JWT.

Recommendation

Upgrade to version 1.21.2 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-285"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T19:02:48Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / @sap-cloud-sdk/core

Package

Name
@sap-cloud-sdk/core
View open source insights on deps.dev
Purl
pkg:npm/%40sap-cloud-sdk/core

Affected ranges

Type
SEMVER
Events
Introduced
1.19.0
Fixed
1.21.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-r2vw-jgq9-jqx2/GHSA-r2vw-jgq9-jqx2.json"