PT-2019-5315 · Connect2Id · Nimbus Jose+Jwt

Published

2019-10-07

·

Updated

2022-06-07

·

CVE-2019-17195

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Connect2id Nimbus JOSE+JWT versions prior to 7.9
Description The issue is related to insufficient checking of unusual or exceptional states in the Java library Nimbus JOSE + JWT. This can be exploited by a remote attacker to cause a denial of service or gain unauthorized access to protected information. The vulnerability may result in an application crash, potentially disclosing information, or a potential authentication bypass when parsing a JWT.
Recommendations For versions prior to 7.9, update to version 7.9 or later to resolve the issue. As a temporary workaround, consider implementing additional error handling for uncaught exceptions when parsing JWTs to minimize the risk of application crashes or information disclosure. Restrict access to sensitive information and authentication mechanisms until the update is applied.

Exploit

Fix

Improper Handling of Exceptional Conditions

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02364
CVE-2019-17195
GHSA-F6VF-PQ8C-69M4
OESA-2021-1269
RHSA-2020:1308

Affected Products

Nimbus Jose+Jwt