| Added |
CPE Configuration |
|
OR
*cpe:2.3:a:auth0:jsonwebtoken:*:*:*:*:*:node.js:*:* versions up to (excluding) 4.2.2 |
| Added |
CVSS V2 |
|
(AV:N/AC:L/Au:N/C:P/I:P/A:P) |
| Added |
CVSS V3 |
|
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Added |
CWE |
|
CWE-327 |
| Changed |
Reference Type |
https://auth0.com/blog/2015/03/31/critical-vulnerabilities-in-json-web-token-libraries/ No Types Assigned |
https://auth0.com/blog/2015/03/31/critical-vulnerabilities-in-json-web-token-libraries/ Broken Link, Vendor Advisory |
| Changed |
Reference Type |
https://github.com/auth0/node-jsonwebtoken/commit/1bb584bc382295eeb7ee8c4452a673a77a68b687 No Types Assigned |
https://github.com/auth0/node-jsonwebtoken/commit/1bb584bc382295eeb7ee8c4452a673a77a68b687 Patch, Third Party Advisory |
| Changed |
Reference Type |
https://nodesecurity.io/advisories/17 No Types Assigned |
https://nodesecurity.io/advisories/17 Third Party Advisory |
| Changed |
Reference Type |
https://www.timmclean.net/2015/02/25/jwt-alg-none.html No Types Assigned |
https://www.timmclean.net/2015/02/25/jwt-alg-none.html Exploit, Third Party Advisory |