Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Dmako

#24981of 53,624
9.8Total CVSS
Vulnerabilities · 1
PT-2018-9301
9.8
2018-03-13
Inversoft · Prime-Jwt · CVE-2018-1000125
Name of the Vulnerable Software and Affected Versions: inversoft prime-jwt versions prior to 1.3.0 Description: The issue concerns an input validation vulnerability in the `JWTDecoder.decode` function. This vulnerability can be exploited by an attacker crafting a token with a valid header and body, which can then be requested for validation, potentially allowing a JWT to be decoded and implicitly validated even if it lacks a valid signature. Recommendations: For inversoft prime-jwt versions prior to 1.3.0, update to version 1.3.0 or later to resolve the issue.