Incorrect Access Control in JWT Security Token for perl-CRYPT-JWT by DCIT
CVE-2019-1010161
9.8CRITICAL
What is CVE-2019-1010161?
The perl-CRYPT-JWT library incorporates a vulnerability in the JWT.pm component, specifically at line 614 in the _decode_jws() function, which enables unauthorized users to bypass authentication mechanisms. This flaw arises due to incorrect access control in versions 0.022 and earlier, allowing attackers to exploit network connectivity and manipulate user-controlled input for authentication evasion. Users are urged to upgrade to version 0.023 to mitigate this risk.
Affected Version(s)
perl-CRYPT-JWT 0.022 and earlier [fixed: 0.023]