Vulnerabilities/

JWS and JWT signature validation vulnerability with special characters

Severity:
High

Description

Jsrsasign supports JWS(JSON Web Signatures) and JWT(JSON Web Token) validation. However JWS or JWT signature with non Base64URL encoding special characters or number escaped characters may be validated as valid by mistake.

Recommendation

Update the jsrsasign package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
jsrsasign
Anything's wrong? Let us know Last updated on January 27, 2023

This issue is available in SmartScanner Professional

See Pricing