{"id":"GHSA-hxhc-wmg8-xrqf","aliases":[],"url":"https://o3.security/vulnerability/GHSA-hxhc-wmg8-xrqf","summary":"namshi/jose insecure JSON Web Signatures (JWS)","details":"namshi/jose allows the acceptance of unsecure JSON Web Signatures (JWS) by default. The vulnerability arises from the $allowUnsecure flag, which, when set to true during the loading of JWSes, permits tokens signed with 'none' algorithms to be processed. This behavior poses a significant security risk as it could allow an attacker to impersonate users by crafting a valid jwt token.","published":"2024-05-17T22:31:42Z","modified":"2024-12-02T05:44:05.646157Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"namshi/jose","fixedVersion":"1.1.2"},{"ecosystem":"Packagist","name":"namshi/jose","fixedVersion":"1.2.2"},{"ecosystem":"Packagist","name":"namshi/jose","fixedVersion":"2.0.3"},{"ecosystem":"Packagist","name":"namshi/jose","fixedVersion":"2.1.2"}],"fix":{"url":"https://github.com/namshi/jose/commit/009f86d6ced000b806b2f602c0b7393060ebb34e","label":"namshi/jose@009f86d"},"references":[{"type":"WEB","url":"https://github.com/namshi/jose/commit/009f86d6ced000b806b2f602c0b7393060ebb34e"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/namshi/jose/2015-02-19.yaml"},{"type":"PACKAGE","url":"https://github.com/namshi/jose"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:44:05.646157Z"}}