PT-2018-6764 · Authentikat · Authentikat-Jwt

Anfedorov

·

Published

2018-03-18

·

Updated

2019-10-03

·

CVE-2017-18239

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: authentikat-jwt versions 0.4.5 and earlier
Description: A time-sensitive equality check on the JWT signature in the JsonWebToken.validate method allows the supplier of a JWT token to guess bit after bit of the signature by repeating validation requests.
Recommendations: For versions 0.4.5 and earlier, consider disabling the JsonWebToken.validate method until a patch is available. Restrict access to the JsonWebToken validation process to minimize the risk of exploitation. Avoid using the JsonWebToken validation for critical authentication processes until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-18239
GHSA-3RHM-67J6-42JQ

Affected Products

Authentikat-Jwt