Vulnerability Description
JWT.php in F21 JWT before 2.0 allows remote attackers to bypass signature verification via crafted tokens.
CVSS Score
5.0
MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| F21 | Jwt | <= 1.0 |
Related Weaknesses (CWE)
References
- http://jvn.jp/en/jp/JVN06120222/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000073Vendor Advisory
- http://www.securityfocus.com/bid/75021
- https://github.com/F21/jwt/commit/a327cf9052df8f9f97728ca0b5fa78a8231b79b6
- http://jvn.jp/en/jp/JVN06120222/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000073Vendor Advisory
- http://www.securityfocus.com/bid/75021
- https://github.com/F21/jwt/commit/a327cf9052df8f9f97728ca0b5fa78a8231b79b6
FAQ
What is CVE-2015-2951?
CVE-2015-2951 is a vulnerability with a CVSS score of 5.0 (MEDIUM). JWT.php in F21 JWT before 2.0 allows remote attackers to bypass signature verification via crafted tokens.
How severe is CVE-2015-2951?
CVE-2015-2951 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-2951?
Check the references section above for vendor advisories and patch information. Affected products include: F21 Jwt.