Vulnerability Description
cdbattags lua-resty-jwt 0.2.3 allows attackers to bypass all JWT-parsing signature checks by crafting a JWT with an enc header with the value A256GCM.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/cdbattags/lua-resty-jwt/commit/d1558e2afefe868fea1e7e9a4b04ea
- https://github.com/cdbattags/lua-resty-jwt/issues/61
- https://insinuator.net/2023/10/lua-resty-jwt-authentication-bypass/
- https://github.com/cdbattags/lua-resty-jwt/commit/d1558e2afefe868fea1e7e9a4b04ea
- https://github.com/cdbattags/lua-resty-jwt/issues/61
- https://insinuator.net/2023/10/lua-resty-jwt-authentication-bypass/
FAQ
What is CVE-2024-33531?
CVE-2024-33531 is a vulnerability with a CVSS score of 8.1 (HIGH). cdbattags lua-resty-jwt 0.2.3 allows attackers to bypass all JWT-parsing signature checks by crafting a JWT with an enc header with the value A256GCM.
How severe is CVE-2024-33531?
CVE-2024-33531 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-33531?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.