PT-2024-27665 · Unknown+4 · Lepture Authlib+4
Emmharnuherl
·
Published
2024-06-09
·
Updated
2026-03-29
·
CVE-2024-37568
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
lepture Authlib versions prior to 1.3.1
Description
The issue concerns algorithm confusion with asymmetric public keys in lepture Authlib. Unless an algorithm is specified in a
jwt.decode call, HMAC verification is allowed with any asymmetric public key.Recommendations
For versions prior to 1.3.1, update to version 1.3.1 or later to resolve the issue. As a temporary workaround, consider specifying an algorithm in
jwt.decode calls to prevent HMAC verification with arbitrary asymmetric public keys.Exploit
Fix
Improper Verification of Cryptographic Signature
Improper Access Control
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Linuxmint
Suse
Ubuntu
Lepture Authlib