VDB
Sign up
MEDIUM4.4

GHSA-7322-jrq4-x5hf

File reference keys leads to incorrect hashes on HMAC algorithms

Quick fix

GHSA-7322-jrq4-x5hf — lcobucci/jwt: upgrade to the fixed version with the command below.

composer require lcobucci/jwt:^3.4.6

Details

### Impact

Users of HMAC-based algorithms (HS256, HS384, and HS512) combined with `Lcobucci\JWT\Signer\Key\LocalFileReference` as key are having their tokens issued/validated using the file path as hashing key - instead of the contents.

The HMAC hashing functions take any string as input and, since users can issue and validate tokens, people are lead to believe that everything works properly.

### Patches

All versions have been patched to always load the file contents, deprecated the `Lcobucci\JWT\Signer\Key\LocalFileReference`, and suggest `Lcobucci\JWT\Signer\Key\InMemory` as the alternative.

### Workarounds

Use `Lcobucci\JWT\Signer\Key\InMemory` instead of `Lcobucci\JWT\Signer\Key\LocalFileReference` to create the instances of your keys:

```diff -use Lcobucci\JWT\Signer\Key\LocalFileReference; +use Lcobucci\JWT\Signer\Key\InMemory;

-$key = LocalFileReference::file(__DIR__ . '/public-key.pem'); +$key = InMemory::file(__DIR__ . '/public-key.pem'); ```

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/lcobucci/jwt
Introduced in: 3.4.0Fixed in: 3.4.6
Fixcomposer require lcobucci/jwt:^3.4.6
Packagist/lcobucci/jwt
Introduced in: 4.0.0Fixed in: 4.0.4
Fixcomposer require lcobucci/jwt:^4.0.4
Packagist/lcobucci/jwt
Introduced in: 4.1.0Fixed in: 4.1.5
Fixcomposer require lcobucci/jwt:^4.1.5

References