Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r65j-6h5f-4f92

Опубликовано: 01 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

Withdrawn: JJWT improperly generates signing keys

Withdrawn Advisory

This advisory has been withdrawn because it has been found to be disputed. Please see the issue here for more information.

Original Description

JJWT (aka Java JWT) through 0.12.5 ignores certain characters and thus a user might falsely conclude that they have a strong key. The impacted code is the setSigningKey() method within the DefaultJwtParser class and the signWith() method within the DefaultJwtBuilder class.

Пакеты

Наименование

io.jsonwebtoken:jjwt-impl

maven
Затронутые версииВерсия исправления

<= 0.12.5

Отсутствует

EPSS

Процентиль: 35%
0.00143
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 6.8
nvd
почти 2 года назад

JJWT (aka Java JWT) through 0.12.5 ignores certain characters and thus a user might falsely conclude that they have a strong key. The impacted code is the setSigningKey() method within the DefaultJwtParser class and the signWith() method within the DefaultJwtBuilder class. NOTE: the vendor disputes this because the "ignores" behavior cannot occur (in any version) unless there is a user error in how JJWT is used, and because the version that was actually tested must have been more than six years out of date.

EPSS

Процентиль: 35%
0.00143
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-327