Impact
A flaw in the SmallRye JWT AwsAlbKeyResolver allows an unauthenticated attacker to send a crafted JWT with a malicious kid header. The resolver concatenates this header directly into the key-fetch URL without sanitizing path traversal or query separators, enabling forced GET requests to arbitrary paths within the same origin as the key endpoint. This remote request can read non-public endpoints or internal data before the JWT signature is validated, potentially exposing sensitive information.
Affected Systems
The vulnerability impacts Red Hat builds that incorporate SmallRye JWT, including Red Hat Build of Quarkus, Red Hat Build of Apicurio Registry 3, Red Hat JBoss Enterprise Application Platform 8, and the Red Hat JBoss Enterprise Application Platform Expansion Pack. Specific affected versions were not listed in the available data, so any release that uses the described AwsAlbKeyResolver without the fix could be vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity; the EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote unauthenticated request that exploits the unsanitized JWT header. Since the flaw allows reading internal resources before authentication, the potential impact ranges from data exposure to facilitating further lateral movement within an organization. Without an official mitigation, the risk remains until the library is updated or the insecure key provider is disabled.
OpenCVE Enrichment