Описание
Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing acceptance of HS384 and HS512 tokens alongside HS256. Attackers possessing the jwtSecret can mint tokens with non-standard HMAC variants to bypass algorithm restrictions and weaken authentication controls.
Ссылки
- Product
- Issue Tracking
- Issue TrackingPatch
- PatchThird Party Advisory
Уязвимые конфигурации
EPSS
4.8 Medium
CVSS3
5.4 Medium
CVSS3
Дефекты
Связанные уязвимости
Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing acceptance of HS384 and HS512 tokens alongside HS256. Attackers possessing the jwtSecret can mint tokens with non-standard HMAC variants to bypass algorithm restrictions and weaken authentication controls.
EPSS
4.8 Medium
CVSS3
5.4 Medium
CVSS3