{"id":"GHSA-8xf4-w7qw-pjjw","summary":"Firebase PHP-JWT key/algorithm type confusion","details":"In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) header, when multiple types of keys are loaded in a key ring. This allows an attacker to forge tokens that validate under the incorrect key. NOTE: this provides a straightforward way to use the PHP-JWT library unsafely, but might not be considered a vulnerability in the library itself.","aliases":["CVE-2021-46743"],"modified":"2023-11-08T04:07:27.311791Z","published":"2022-03-30T00:00:27Z","database_specific":{"github_reviewed_at":"2023-02-17T14:26:38Z","nvd_published_at":"2022-03-29T07:15:00Z","cwe_ids":["CWE-347","CWE-843"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-46743"},{"type":"WEB","url":"https://github.com/firebase/php-jwt/issues/351"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/firebase/php-jwt/CVE-2021-46743.yaml"},{"type":"PACKAGE","url":"https://github.com/firebase/php-jwt"},{"type":"WEB","url":"https://github.com/firebase/php-jwt/releases/tag/v6.0.0"}],"affected":[{"package":{"name":"firebase/php-jwt","ecosystem":"Packagist","purl":"pkg:composer/firebase/php-jwt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.0"}]}],"versions":["1.0.0","2.0.0","v2.1.0","v2.2.0","v3.0.0","v4.0.0","v5.0.0","v5.1.0","v5.2.0","v5.2.1","v5.3.0","v5.4.0","v5.5.0","v5.5.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-8xf4-w7qw-pjjw/GHSA-8xf4-w7qw-pjjw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}