CVE-2016-10555
—CVSS 3.0
6.5 medium
EPSS
5%p92
Published
()
Modified
Description
Since "algorithm" isn't enforced in jwt.decode()in jwt-simple 0.3.0 and earlier, a malicious user could choose what algorithm is sent sent to the server. If the server is expecting RSA but is sent HMAC-SHA with RSA's public key, the server will think the public key is actually an HMAC private key. This could be used to forge any data an attacker wants.
- Vendors
- jwt-simple project
- Products
- jwt-simple
- Weakness
- CWE-20, CWE-310
- Vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.