GHSA-7322-jrq4-x5hf
File reference keys leads to incorrect hashes on HMAC algorithms
Quick fix
GHSA-7322-jrq4-x5hf — lcobucci/jwt: upgrade to the fixed version with the command below.
composer require lcobucci/jwt:^3.4.6Details
### Impact
Users of HMAC-based algorithms (HS256, HS384, and HS512) combined with `Lcobucci\JWT\Signer\Key\LocalFileReference` as key are having their tokens issued/validated using the file path as hashing key - instead of the contents.
The HMAC hashing functions take any string as input and, since users can issue and validate tokens, people are lead to believe that everything works properly.
### Patches
All versions have been patched to always load the file contents, deprecated the `Lcobucci\JWT\Signer\Key\LocalFileReference`, and suggest `Lcobucci\JWT\Signer\Key\InMemory` as the alternative.
### Workarounds
Use `Lcobucci\JWT\Signer\Key\InMemory` instead of `Lcobucci\JWT\Signer\Key\LocalFileReference` to create the instances of your keys:
```diff -use Lcobucci\JWT\Signer\Key\LocalFileReference; +use Lcobucci\JWT\Signer\Key\InMemory;
-$key = LocalFileReference::file(__DIR__ . '/public-key.pem'); +$key = InMemory::file(__DIR__ . '/public-key.pem'); ```
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/lcobucci/jwt/security/advisories/GHSA-7322-jrq4-x5hf[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-41106[ADVISORY]
- https://github.com/lcobucci/jwt/commit/8175de5b841fbe3fd97d2d49b3fc15c4ecb39a73[WEB]
- https://github.com/lcobucci/jwt/commit/c45bb8b961a8e742d8f6b88ef5ff1bd5cca5d01c[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/lcobucci/jwt/CVE-2021-41106.yaml[WEB]
- https://github.com/lcobucci/jwt[PACKAGE]