SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-17195

Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.

CRITICAL 9.8EPSS 11.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 11.0%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
11.03% probability · 96th percentile
CISA KEV
Not listed
Weakness
CWE-755
Affected
connect2id/nimbus jose\+jwt · apache/hadoop · oracle/communications cloud native core security edge protection proxy · oracle/communications pricing design center · oracle/data integrator · oracle/enterprise manager base platform · oracle/healthcare data repository · oracle/insurance policy administration · oracle/jd edwards enterpriseone orchestrator · oracle/jd edwards enterpriseone tools · oracle/peoplesoft enterprise peopletools · oracle/policy automation · oracle/primavera gateway · oracle/solaris cluster · oracle/weblogic server
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.