Описание
reason-jose is a JOSE implementation in ReasonML and OCaml.Jose.Jws.validate does not check HS256 signatures. This allows tampering of JWS header and payload data if the service does not perform additional checks. Such tampering could expose applications using reason-jose to authorization bypass. Applications relying on JWS claims assertion to enforce security boundaries may be vulnerable to privilege escalation. This issue has been patched in version 0.8.2.
Ссылки
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.8.2 (исключая)
cpe:2.3:a:reason-jose_project:reason-jose:*:*:*:*:*:*:*:*
EPSS
Процентиль: 32%
0.00127
Низкий
5.9 Medium
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-347
EPSS
Процентиль: 32%
0.00127
Низкий
5.9 Medium
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-347