CRITICAL
GHSA-h533-5v22-8vcp
firebase/php-jwt: "None" Algorithm treated as valid on tokens
Quick fix
GHSA-h533-5v22-8vcp — firebase/php-jwt: upgrade to the fixed version with the command below.
composer require firebase/php-jwt:^2.0.0Details
Several widely-used JSON Web Token (JWT) libraries, including node-jsonwebtoken, pyjwt, namshi/jose, php-jwt, and jsjwt, are affected by critical vulnerabilities that could allow attackers to bypass the verification step when using asymmetric keys (RS256, RS384, RS512, ES256, ES384, ES512).
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/firebase/php-jwt
Introduced in:
0Fixed in: 2.0.0Fix
composer require firebase/php-jwt:^2.0.0References
- https://github.com/firebase/php-jwt/commit/b2c2be6a45fda769c8c2ffe5ec4259a9d1e46e5b[WEB]
- https://auth0.com/blog/2015/03/31/critical-vulnerabilities-in-json-web-token-libraries[WEB]
- https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/firebase/php-jwt/2015-04-02.yaml[WEB]
- https://github.com/firebase/php-jwt[PACKAGE]