GHSA-9gxv-x7rp-r2hc: gree/jose - "None" Algorithm treated as valid in tokens
(updated )
Several widely-used JSON Web Token (JWT) libraries, including node-jsonwebtoken, pyjwt, namshi/jose, php-jwt, and jsjwt, are affected by critical vulnerabilities that could allow attackers to bypass the verification step when using asymmetric keys (RS256, RS384, RS512, ES256, ES384, ES512).
References
- auth0.com/blog/2015/03/31/critical-vulnerabilities-in-json-web-token-libraries
- auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries
- github.com/FriendsOfPHP/security-advisories/blob/master/gree/jose/2016-08-30.yaml
- github.com/advisories/GHSA-9gxv-x7rp-r2hc
- github.com/nov/jose-php/compare/2.2.0...2.2.1
Code Behaviors & Features
Detect and mitigate GHSA-9gxv-x7rp-r2hc with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →