SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-23541

jsonwebtoken is an implementation of JSON Web Tokens.

MEDIUM 6.3EPSS 0.75%

Does this matter?

Lower severity and a low EPSS score (0.75%). Track it; it rarely justifies an emergency change on its own.

Description

jsonwebtoken is an implementation of JSON Web Tokens. Versions `<= 8.5.1` of `jsonwebtoken` library can be misconfigured so that passing a poorly implemented key retrieval function referring to the `secretOrPublicKey` argument from the readme link will result in incorrect verification of tokens. There is a possibility of using a different algorithm and key combination in verification, other than the one that was used to sign the tokens. Specifically, tokens signed with an asymmetric public key could be verified with a symmetric HS256 algorithm. This can lead to successful validation of forged tokens. If your application is supporting usage of both symmetric key and asymmetric key in jwt.verify() implementation with the same key retrieval function. This issue has been patched, please update to version 9.0.0.

CVSS 3.1
6.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS
0.75% probability · 53th percentile
CISA KEV
Not listed
Weakness
CWE-287, CWE-1259
Affected
auth0/jsonwebtoken
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.