Input Validation Flaw in Inversoft Prime JWT Affects Security Integrity
CVE-2018-1000125

9.8CRITICAL

Key Information:

Vendor

Inversoft

Status
Vendor
CVE Published:
13 March 2018

What is CVE-2018-1000125?

An input validation vulnerability exists in Inversoft Prime JWT prior to version 1.3.0, specifically within the JWTDecoder.decode function. This flaw allows an attacker to create a malicious JSON Web Token (JWT) with a valid header and body, enabling the token to be decoded and validated without a legitimate signature. Such exploitation poses a significant risk as it undermines the security of token validation processes. The issue has been addressed in version 1.3.0 and later, as well as following the specified commit.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.