ZeroHour

CVE-2019-7644

CVSS 3.0
9.8 critical
EPSS
2%p76
Published
()
Modified
Description

Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT signature. If this error message is presented to an attacker, they can forge an arbitrary JWT token that will be accepted by the vulnerable application.

Vendors
auth0
Products
auth0-wcf-service-jwt
Weakness
CWE-209
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.