auth0 Node Jsonwebtoken Vulnerabilities
Auth0 Node-jsonwebtoken vulnerabilities.
Vulnerability Published:
ποΈ Published
- Anytime
Sort By:
ποΈ Published Date
- Descending
jsonwebtoken unrestricted key type could lead to legacy keys usage
CVE-2022-23539Auth0Node-jsonwebtoken5.9MEDIUMjsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
CVE-2022-23540Auth0Node-jsonwebtoken7.6HIGHjsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC
CVE-2022-23541Auth0Node-jsonwebtoken5MEDIUM