Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2022-39227

почти 4 года назад

python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key. Depending on the application, this may for example enable the attacker to spoof other user's identities, hijack their sessions, or bypass authentication. Users should upgrade to version 3.3.4. There are no known workarounds.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2022-39227

почти 4 года назад

python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key. Depending on the application, this may for example enable the attacker to spoof other user's identities, hijack their sessions, or bypass authentication. Users should upgrade to version 3.3.4. There are no known workarounds.

CVSS3: 9.1
EPSS: Низкий
msrc логотип

CVE-2022-39227

почти 4 года назад

Python-jwt subject to Authentication Bypass by Spoofing

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-5p8v-58qm-c7fp

почти 4 года назад

python-jwt vulnerable to token forgery with new claims

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-39227

python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key. Depending on the application, this may for example enable the attacker to spoof other user's identities, hijack their sessions, or bypass authentication. Users should upgrade to version 3.3.4. There are no known workarounds.

CVSS3: 9.1
4%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-39227

python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key. Depending on the application, this may for example enable the attacker to spoof other user's identities, hijack their sessions, or bypass authentication. Users should upgrade to version 3.3.4. There are no known workarounds.

CVSS3: 9.1
4%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-39227

Python-jwt subject to Authentication Bypass by Spoofing

CVSS3: 9.1
4%
Низкий
почти 4 года назад
github логотип
GHSA-5p8v-58qm-c7fp

python-jwt vulnerable to token forgery with new claims

CVSS3: 9.1
4%
Низкий
почти 4 года назад

Уязвимостей на страницу