gree/jose - "None" Algorithm treated as valid in tokens
Critical severity
GitHub Reviewed
Published
May 15, 2024
to the GitHub Advisory Database
Description
Published to the GitHub Advisory Database
May 15, 2024
Reviewed
May 15, 2024
Several widely-used JSON Web Token (JWT) libraries, including node-jsonwebtoken, pyjwt, namshi/jose, php-jwt, and jsjwt, are affected by critical vulnerabilities that could allow attackers to bypass the verification step when using asymmetric keys (RS256, RS384, RS512, ES256, ES384, ES512).
References