VDB
Sign up
CRITICAL

GHSA-c7hr-j4mj-j2w6

Verification Bypass in jsonwebtoken

Quick fix

GHSA-c7hr-j4mj-j2w6 — jsonwebtoken: upgrade to the fixed version with the command below.

npm install jsonwebtoken@4.2.2

Details

Versions 4.2.1 and earlier of `jsonwebtoken` are affected by a verification bypass vulnerability. This is a result of weak validation of the JWT algorithm type, occuring when an attacker is allowed to arbitrarily specify the JWT algorithm.

## Recommendation

Update to version 4.2.2 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jsonwebtoken
Introduced in: 0Fixed in: 4.2.2
Fixnpm install jsonwebtoken@4.2.2

References