CRITICAL
GHSA-4rr6-gf59-ggw5
namshi/jose - Verification bypass
Quick fix
GHSA-4rr6-gf59-ggw5 — namshi/jose: upgrade to the fixed version with the command below.
composer require namshi/jose:^2.2.0Details
Several widely-used JSON Web Token (JWT) libraries, including node-jsonwebtoken, pyjwt, namshi/jose, php-jwt, and jsjwt, are affected by critical vulnerabilities that could allow attackers to bypass the verification step when using asymmetric keys (RS256, RS384, RS512, ES256, ES384, ES512).
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://auth0.com/blog/2015/03/31/critical-vulnerabilities-in-json-web-token-libraries[WEB]
- https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/namshi/jose/2015-03-10.yaml[WEB]
- https://github.com/namshi/jose[PACKAGE]