PT-2018-4705 · Hapi · Hapi-Auth-Jwt2

Publicado

2018-05-29

·

Atualizado

2019-02-18

·

CVE-2016-10525

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions hapi-auth-jwt2 versions prior to 5.1.2
Description The issue allows for a complete authentication bypass when in the try authentication mode. This means that individuals could bypass the authentication process.
Recommendations Update to version 5.1.2 or later. As a temporary workaround, consider disabling the try authentication mode until the update is applied. Restrict access to sensitive areas of the application to minimize the risk of exploitation.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-10525
GHSA-MG8R-9G6J-HWV9

Produtos afetados

Hapi-Auth-Jwt2