VDB
Sign up
MEDIUM6.4

GHSA-qwph-4952-7xr6

jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()

Quick fix

GHSA-qwph-4952-7xr6 — jsonwebtoken: upgrade to the fixed version with the command below.

npm install jsonwebtoken@9.0.0

Details

# Overview

In versions <=8.5.1 of jsonwebtoken library, lack of algorithm definition and a falsy secret or key in the `jwt.verify()` function can lead to signature validation bypass due to defaulting to the `none` algorithm for signature verification.

# Am I affected? You will be affected if all the following are true in the `jwt.verify()` function: - a token with no signature is received - no algorithms are specified - a falsy (e.g. null, false, undefined) secret or key is passed

# How do I fix it? Update to version 9.0.0 which removes the default support for the none algorithm in the `jwt.verify()` method.

# Will the fix impact my users?

There will be no impact, if you update to version 9.0.0 and you don’t need to allow for the `none` algorithm. If you need 'none' algorithm, you have to explicitly specify that in `jwt.verify()` options.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jsonwebtoken
Introduced in: 0Fixed in: 9.0.0
Fixnpm install jsonwebtoken@9.0.0

References