VDB
Sign up
CRITICAL9.1

GHSA-8xf4-w7qw-pjjw

Firebase PHP-JWT key/algorithm type confusion

Quick fix

GHSA-8xf4-w7qw-pjjw — firebase/php-jwt: upgrade to the fixed version with the command below.

composer require firebase/php-jwt:^6.0.0

Details

In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) header, when multiple types of keys are loaded in a key ring. This allows an attacker to forge tokens that validate under the incorrect key. NOTE: this provides a straightforward way to use the PHP-JWT library unsafely, but might not be considered a vulnerability in the library itself.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/firebase/php-jwt
Introduced in: 0Fixed in: 6.0.0
Fixcomposer require firebase/php-jwt:^6.0.0

References