PT-2019-5315 · Connect2Id · Nimbus Jose+Jwt
Published
2019-10-07
·
Updated
2022-06-07
·
CVE-2019-17195
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Connect2id Nimbus JOSE+JWT versions prior to 7.9
Description
The issue is related to insufficient checking of unusual or exceptional states in the Java library Nimbus JOSE + JWT. This can be exploited by a remote attacker to cause a denial of service or gain unauthorized access to protected information. The vulnerability may result in an application crash, potentially disclosing information, or a potential authentication bypass when parsing a JWT.
Recommendations
For versions prior to 7.9, update to version 7.9 or later to resolve the issue. As a temporary workaround, consider implementing additional error handling for uncaught exceptions when parsing JWTs to minimize the risk of application crashes or information disclosure. Restrict access to sensitive information and authentication mechanisms until the update is applied.
Exploit
Fix
Improper Handling of Exceptional Conditions
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nimbus Jose+Jwt