{"id":"GHSA-mg8r-9g6j-hwv9","summary":"Authentication Bypass in hapi-auth-jwt2","details":"Versions of `hapi-auth-jwt2` prior to version 5.1.2 are affected by a complete authentication bypass vulnerability when in the `try` authentication mode. \n\n\n## Recommendation\n\nUpdate to version 5.1.2 or later.","aliases":["CVE-2016-10525"],"modified":"2023-11-08T03:58:10.538387Z","published":"2019-02-18T23:39:00Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:46:04Z","nvd_published_at":null,"cwe_ids":["CWE-287"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-10525"},{"type":"WEB","url":"https://github.com/dwyl/hapi-auth-jwt2/issues/111"},{"type":"WEB","url":"https://github.com/dwyl/hapi-auth-jwt2/pull/112"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mg8r-9g6j-hwv9"},{"type":"PACKAGE","url":"https://github.com/dwyl/hapi-auth-jwt2"},{"type":"WEB","url":"https://www.npmjs.com/advisories/81"}],"affected":[{"package":{"name":"hapi-auth-jwt2","ecosystem":"npm","purl":"pkg:npm/hapi-auth-jwt2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.1.1"},{"fixed":"5.1.2"}]}],"versions":["5.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/02/GHSA-mg8r-9g6j-hwv9/GHSA-mg8r-9g6j-hwv9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}