{"id":"GHSA-vgrx-w6rg-8fqf","summary":"Forgeable Public/Private Tokens in jwt-simple","details":"Affected versions of the `jwt-simple` package allow users to select what algorithm the server will use to verify a provided JWT. A malicious actor can use this behaviour to arbitrarily modify the contents of a JWT while still passing verification. For the common use case of the JWT, the end result is a complete authentication bypass with minimal effort.\n\n\n\n## Recommendation\n\nUpdate to version 0.3.1 or later.\n\nAdditionally, be sure to always specify an algorithm in calls to `.decode()`.","aliases":["CVE-2016-10555"],"modified":"2023-11-08T03:58:12.325695Z","published":"2018-11-06T23:12:07Z","database_specific":{"github_reviewed_at":"2020-06-16T21:57:45Z","nvd_published_at":null,"cwe_ids":["CWE-20"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-10555"},{"type":"WEB","url":"https://github.com/hokaccha/node-jwt-simple/pull/14"},{"type":"WEB","url":"https://github.com/hokaccha/node-jwt-simple/pull/16"},{"type":"WEB","url":"https://github.com/hokaccha/node-jwt-simple/commit/957957cfa44474049b4603b293569588ee9ffd97"},{"type":"WEB","url":"https://auth0.com/blog/2015/03/31/critical-vulnerabilities-in-json-web-token-libraries"},{"type":"WEB","url":"https://www.npmjs.com/advisories/87"}],"affected":[{"package":{"name":"jwt-simple","ecosystem":"npm","purl":"pkg:npm/jwt-simple"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.3.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/11/GHSA-vgrx-w6rg-8fqf/GHSA-vgrx-w6rg-8fqf.json"}}],"schema_version":"1.9.0"}