VDB
Sign up
HIGH

GHSA-hxhc-wmg8-xrqf

namshi/jose insecure JSON Web Signatures (JWS)

Quick fix

GHSA-hxhc-wmg8-xrqf — namshi/jose: upgrade to the fixed version with the command below.

composer require namshi/jose:^1.1.2

Details

namshi/jose allows the acceptance of unsecure JSON Web Signatures (JWS) by default. The vulnerability arises from the $allowUnsecure flag, which, when set to true during the loading of JWSes, permits tokens signed with 'none' algorithms to be processed. This behavior poses a significant security risk as it could allow an attacker to impersonate users by crafting a valid jwt token.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/namshi/jose
Introduced in: 0Fixed in: 1.1.2
Fixcomposer require namshi/jose:^1.1.2
Packagist/namshi/jose
Introduced in: 1.2.0Fixed in: 1.2.2
Fixcomposer require namshi/jose:^1.2.2
Packagist/namshi/jose
Introduced in: 2.0.0Fixed in: 2.0.3
Fixcomposer require namshi/jose:^2.0.3
Packagist/namshi/jose
Introduced in: 2.1.0Fixed in: 2.1.2
Fixcomposer require namshi/jose:^2.1.2

References