PT-2020-16905 · Servicestack · Servicestack
Published
2020-03-11
·
Updated
2021-01-13
·
CVE-2020-28042
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ServiceStack versions prior to 5.9.2
Description
The issue is related to the mishandling of JWT signature verification. This occurs unless an application has a custom
ValidateToken function that establishes a valid minimum length for a signature.Recommendations
For versions prior to 5.9.2, update to version 5.9.2 or later to resolve the issue. As a temporary workaround, consider implementing a custom
ValidateToken function that establishes a valid minimum length for a signature to mitigate the risk of exploitation.Exploit
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Servicestack