ZeroHour

CVE-2019-17195

CVSS 3.1
9.8 critical
EPSS
11%p96
Published
()
Modified
Description

Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.

Vendors
connect2idapacheoracle
Products
nimbus jose\+jwt, hadoop, communications cloud native core security edge protection proxy, communications pricing design center, data integrator, enterprise manager base platform, healthcare data repository, insurance policy administration, jd edwards enterpriseone orchestrator, jd edwards enterpriseone tools, peoplesoft enterprise peopletools, policy automation
Weakness
CWE-755
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.