← Retour aux CVEs
CVE-2018-1000531
N/ADescription
inversoft prime-jwt version prior to commit abb0d479389a2509f939452a6767dc424bb5e6ba contains a CWE-20 vulnerability in JWTDecoder.decode that can result in an incorrect signature validation of a JWT token. This attack can be exploitable when an attacker crafts a JWT token with a valid header using 'none' as algorithm and a body to requests it be validated. This vulnerability was fixed after commit abb0d479389a2509f939452a6767dc424bb5e6ba.
Details CVE
Score CVSS v3.1N/A
Publie6/26/2018
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
inversoft:prime-jwt
Faiblesses (CWE)
CWE-20
References
https://github.com/inversoft/prime-jwt/issues/3(cve@mitre.org)
https://github.com/inversoft/prime-jwt/issues/3(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.