Описание
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that pass signature verification. When key=None is passed to any JWS deserialization function, the library extracts and uses the cryptographic key embedded in the attacker-controlled JWT jwk header field. An attacker can sign a token with their own private key, embed the matching public key in the header, and have the server accept the forged token as cryptographically valid — bypassing authentication and authorization entirely. This issue has been patched in version 1.6.9.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needs-triage | |
| esm-apps/jammy | released | 0.15.5-1ubuntu0.1~esm2 |
| esm-apps/noble | released | 1.3.0-1ubuntu0.1~esm2 |
| esm-apps/resolute | released | 1.6.7-1ubuntu0.1~esm1 |
| jammy | needed | |
| noble | needed | |
| questing | ignored | end of life, was needs-triage |
| resolute | needed | |
| upstream | released | 1.6.9-1 |
Показывать по
EPSS
9.1 Critical
CVSS3
Связанные уязвимости
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that pass signature verification. When key=None is passed to any JWS deserialization function, the library extracts and uses the cryptographic key embedded in the attacker-controlled JWT jwk header field. An attacker can sign a token with their own private key, embed the matching public key in the header, and have the server accept the forged token as cryptographically valid — bypassing authentication and authorization entirely. This issue has been patched in version 1.6.9.
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that pass signature verification. When key=None is passed to any JWS deserialization function, the library extracts and uses the cryptographic key embedded in the attacker-controlled JWT jwk header field. An attacker can sign a token with their own private key, embed the matching public key in the header, and have the server accept the forged token as cryptographically valid — bypassing authentication and authorization entirely. This issue has been patched in version 1.6.9.
Authlib is a Python library which builds OAuth and OpenID Connect serv ...
Authlib JWS JWK Header Injection: Signature Verification Bypass
Уязвимость реализации JOSE библиотеки Authlib для серверов OAuth и OpenID Connect, связанная с недостаточной проверкой подлинности данных, позволяющая нарушителю выполнить произвольный код
EPSS
9.1 Critical
CVSS3