Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-9235

Опубликовано: 29 мая 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but instead the attacker send a token digitally signed with a symmetric algorithm (HS* family).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:auth0:jsonwebtoken:*:*:*:*:*:node.js:*:*
Версия до 4.2.2 (исключая)

EPSS

Процентиль: 95%
0.08655
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-20
CWE-327

Связанные уязвимости

CVSS3: 7.3
redhat
больше 8 лет назад

In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but instead the attacker send a token digitally signed with a symmetric algorithm (HS* family).

github
почти 8 лет назад

Verification Bypass in jsonwebtoken

EPSS

Процентиль: 95%
0.08655
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-20
CWE-327