Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-23928

Опубликовано: 01 фев. 2023
Источник: nvd
CVSS3: 5.9
CVSS3: 9.8
EPSS Низкий

Описание

reason-jose is a JOSE implementation in ReasonML and OCaml.Jose.Jws.validate does not check HS256 signatures. This allows tampering of JWS header and payload data if the service does not perform additional checks. Such tampering could expose applications using reason-jose to authorization bypass. Applications relying on JWS claims assertion to enforce security boundaries may be vulnerable to privilege escalation. This issue has been patched in version 0.8.2.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:reason-jose_project:reason-jose:*:*:*:*:*:*:*:*
Версия до 0.8.2 (исключая)

EPSS

Процентиль: 32%
0.00127
Низкий

5.9 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-347

EPSS

Процентиль: 32%
0.00127
Низкий

5.9 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-347