PT-2018-4705 · Hapi · Hapi-Auth-Jwt2

Published

2018-05-29

·

Updated

2019-02-18

·

CVE-2016-10525

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions hapi-auth-jwt2 versions prior to 5.1.2
Description The issue allows for a complete authentication bypass when in the try authentication mode. This means that individuals could bypass the authentication process.
Recommendations Update to version 5.1.2 or later. As a temporary workaround, consider disabling the try authentication mode until the update is applied. Restrict access to sensitive areas of the application to minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10525
GHSA-MG8R-9G6J-HWV9

Affected Products

Hapi-Auth-Jwt2