Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-93c7-w42j-xh4p

Опубликовано: 30 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.3
CVSS3: 4.8

Описание

Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing acceptance of HS384 and HS512 tokens alongside HS256. Attackers possessing the jwtSecret can mint tokens with non-standard HMAC variants to bypass algorithm restrictions and weaken authentication controls.

Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing acceptance of HS384 and HS512 tokens alongside HS256. Attackers possessing the jwtSecret can mint tokens with non-standard HMAC variants to bypass algorithm restrictions and weaken authentication controls.

EPSS

Процентиль: 4%
0.00147
Низкий

6.3 Medium

CVSS4

4.8 Medium

CVSS3

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 4.8
nvd
2 месяца назад

Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing acceptance of HS384 and HS512 tokens alongside HS256. Attackers possessing the jwtSecret can mint tokens with non-standard HMAC variants to bypass algorithm restrictions and weaken authentication controls.

EPSS

Процентиль: 4%
0.00147
Низкий

6.3 Medium

CVSS4

4.8 Medium

CVSS3

Дефекты

CWE-327