{"id":"CVE-2016-1000223","aliases":[],"url":"https://o3.security/vulnerability/CVE-2016-1000223","summary":"Forgeable Public/Private Tokens in jws","details":"Affected versions of the `jws` package allow users to select what algorithm the server will use to verify a provided JWT. A malicious actor can use this behaviour to arbitrarily modify the contents of a JWT while still passing verification. For the common use case of the JWT as a bearer token, the end result is a complete authentication bypass with minimal effort.\n\n\n\n\n## Recommendation\n\nUpdate to version 3.0.0 or later.","published":"2020-09-01T15:23:18Z","modified":"2023-11-08T03:58:07.352660Z","cvss":{"score":8.7,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"jws","fixedVersion":"3.0.0"}],"fix":{"url":"https://github.com/brianloveswords/node-jws/commit/585d0e1e97b6747c10cf5b7689ccc5618a89b299#diff-4ac32a78649ca5bdd8e0ba38b7006a1e","label":"brianloveswords/node-jws@585d0e1"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-1000223"},{"type":"WEB","url":"https://github.com/brianloveswords/node-jws/commit/585d0e1e97b6747c10cf5b7689ccc5618a89b299#diff-4ac32a78649ca5bdd8e0ba38b7006a1e"},{"type":"WEB","url":"https://auth0.com/blog/2015/03/31/critical-vulnerabilities-in-json-web-token-libraries"},{"type":"PACKAGE","url":"https://github.com/brianloveswords/node-jws"},{"type":"WEB","url":"https://snyk.io/vuln/npm:jws:20160726"},{"type":"WEB","url":"https://www.npmjs.com/advisories/88"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:58:07.352660Z"}}