In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but instead the attacker send a token digitally signed with a symmetric algorithm (HS* family).
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAuth0 Jsonwebtoken
APPAuth0< 4.2.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
References
Related vulnerabilities
CVE-2022-23539MEDIUM5.9same product
Versions `<=8.5.1` of `jsonwebtoken` library could be misconfigured so that legacy, insecure key types are use...
CVE-2022-23540MEDIUM6.4same product
In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function c...
CVE-2022-23541MEDIUM5.0same product
jsonwebtoken is an implementation of JSON Web Tokens. Versions `<= 8.5.1` of `jsonwebtoken` library can be mis...
CVE-2020-7947CRITICAL9.8PL ✓same vendor
CSV injection w pluginie Login by Auth0 dla WordPress (przed 4.0.0)
CVE-2019-7644CRITICAL9.8PL ✓same vendor
Auth0 WCF Service JWT — wyciek sygnatury tokenu w komunikacie błędu