VDB
Sign up
HIGH8.7

GHSA-gjcw-v447-2w7q

Forgeable Public/Private Tokens in jws

Quick fix

GHSA-gjcw-v447-2w7q — jws: upgrade to the fixed version with the command below.

npm install jws@3.0.0

Details

Affected versions of the `jws` package allow users to select what algorithm the server will use to verify a provided JWT. A malicious actor can use this behaviour to arbitrarily modify the contents of a JWT while still passing verification. For the common use case of the JWT as a bearer token, the end result is a complete authentication bypass with minimal effort.

## Recommendation

Update to version 3.0.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jws
Introduced in: 0Fixed in: 3.0.0
Fixnpm install jws@3.0.0

References