Skip to main content

Vendor/product archive

auth0 / jsonwebtoken CVEs

Beta · best-effort

4 CVEs tagged to auth0 / jsonwebtoken1 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2022-23539

Published Dec 23, 2022

Versions `<=8.5.1` of `jsonwebtoken` library could be misconfigured so that legacy, insecure key types are used for signature verification. For example, DSA keys could be used wit…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23540

Published Dec 22, 2022

In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass due to defaulting to the `none…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23541

Published Dec 22, 2022

jsonwebtoken is an implementation of JSON Web Tokens. Versions `<= 8.5.1` of `jsonwebtoken` library can be misconfigured so that passing a poorly implemented key retrieval functio…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-9235

Published May 29, 2018

In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms bu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1