Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
Hadoop
Subscribe
|
|
Connect2id
Subscribe
|
Nimbus Jose\+jwt
Subscribe
|
|
Oracle
Subscribe
|
Communications Cloud Native Core Security Edge Protection Proxy
Subscribe
Communications Pricing Design Center
Subscribe
Data Integrator
Subscribe
Enterprise Manager Base Platform
Subscribe
Healthcare Data Repository
Subscribe
Insurance Policy Administration
Subscribe
Jd Edwards Enterpriseone Orchestrator
Subscribe
Jd Edwards Enterpriseone Tools
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Policy Automation
Subscribe
Primavera Gateway
Subscribe
Solaris Cluster
Subscribe
Weblogic Server
Subscribe
|
|
Redhat
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f6vf-pq8c-69m4 | Improper Check for Unusual or Exceptional Conditions in Connect2id Nimbus JOSE+JWT |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T01:33:17.304Z
Reserved: 2019-10-05T00:00:00
Link: CVE-2019-17195
No data.
Status : Modified
Published: 2019-10-15T14:15:12.380
Modified: 2024-11-21T04:31:50.293
Link: CVE-2019-17195
OpenCVE Enrichment
No data.
Github GHSA