Vulnerabilities/

Cisco node-jose improper validation of JWT signature

Severity:
High

Description

A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens using a key that is embedded within the token. The vulnerability is due to node-jose following the JSON Web Signature (JWS) standard for JSON Web Tokens (JWTs).

Recommendation

Update the node-jose package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
node-jose
Anything's wrong? Let us know Last updated on October 14, 2023

This issue is available in SmartScanner Professional

See Pricing