Description
The package jsrsasign before 10.5.25 are vulnerable to Improper Verification of Cryptographic Signature when JWS or JWT signature with non Base64URL encoding special characters or number escaped characters may be validated as valid by mistake. Workaround: Validate JWS or JWT signature if it has Base64URL and dot safe string before executing JWS.verify() or JWS.verifyJWT() method.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5902 | The package jsrsasign before 10.5.25 are vulnerable to Improper Verification of Cryptographic Signature when JWS or JWT signature with non Base64URL encoding special characters or number escaped characters may be validated as valid by mistake. Workaround: Validate JWS or JWT signature if it has Base64URL and dot safe string before executing JWS.verify() or JWS.verifyJWT() method. |
Github GHSA |
GHSA-3fvg-4v2m-98jf | JWS and JWT signature validation vulnerability with special characters |
References
History
No history.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-09-16T18:48:35.777Z
Reserved: 2022-02-24T00:00:00.000Z
Link: CVE-2022-25898
No data.
Status : Modified
Published: 2022-07-01T20:15:08.023
Modified: 2024-11-21T06:53:11.150
Link: CVE-2022-25898
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA