PT-2022-12914 · Firebase+1 · Firebase Php-Jwt+1

Paragonie-Security

·

Published

2022-03-29

·

Updated

2024-04-04

·

CVE-2021-46743

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Firebase PHP-JWT versions prior to 6.0.0
Description The issue is related to an algorithm-confusion problem, where an attacker can forge tokens that validate under the incorrect key when multiple types of keys are loaded in a key ring. This occurs via the kid (Key ID) header.
Recommendations For versions prior to 6.0.0, update to version 6.0.0 or later to resolve the issue.

Exploit

Fix

Type Confusion

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1879
ALT-PU-2024-4537
ALT-PU-2024-4547
ALT-PU-2024-4961
CVE-2021-46743
GHSA-8XF4-W7QW-PJJW

Affected Products

Alt Linux
Firebase Php-Jwt