Логотип exploitDog
bind:CVE-2022-39227
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-39227

Количество 4

Количество 4

redhat логотип

CVE-2022-39227

больше 3 лет назад

python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key. Depending on the application, this may for example enable the attacker to spoof other user's identities, hijack their sessions, or bypass authentication. Users should upgrade to version 3.3.4. There are no known workarounds.

CVSS3: 9.1
EPSS: Средний
nvd логотип

CVE-2022-39227

больше 3 лет назад

python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key. Depending on the application, this may for example enable the attacker to spoof other user's identities, hijack their sessions, or bypass authentication. Users should upgrade to version 3.3.4. There are no known workarounds.

CVSS3: 9.1
EPSS: Средний
msrc логотип

CVE-2022-39227

больше 3 лет назад

CVSS3: 9.1
EPSS: Средний
github логотип

GHSA-5p8v-58qm-c7fp

больше 3 лет назад

python-jwt vulnerable to token forgery with new claims

CVSS3: 9.1
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-39227

python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key. Depending on the application, this may for example enable the attacker to spoof other user's identities, hijack their sessions, or bypass authentication. Users should upgrade to version 3.3.4. There are no known workarounds.

CVSS3: 9.1
69%
Средний
больше 3 лет назад
nvd логотип
CVE-2022-39227

python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key. Depending on the application, this may for example enable the attacker to spoof other user's identities, hijack their sessions, or bypass authentication. Users should upgrade to version 3.3.4. There are no known workarounds.

CVSS3: 9.1
69%
Средний
больше 3 лет назад
msrc логотип
CVSS3: 9.1
69%
Средний
больше 3 лет назад
github логотип
GHSA-5p8v-58qm-c7fp

python-jwt vulnerable to token forgery with new claims

CVSS3: 9.1
69%
Средний
больше 3 лет назад

Уязвимостей на страницу