Input Validation Flaw in Inversoft Prime JWT Affects Security Integrity
CVE-2018-1000125
9.8CRITICAL
What is CVE-2018-1000125?
An input validation vulnerability exists in Inversoft Prime JWT prior to version 1.3.0, specifically within the JWTDecoder.decode function. This flaw allows an attacker to create a malicious JSON Web Token (JWT) with a valid header and body, enabling the token to be decoded and validated without a legitimate signature. Such exploitation poses a significant risk as it undermines the security of token validation processes. The issue has been addressed in version 1.3.0 and later, as well as following the specified commit.