CVE-2021-29455
Summary
| CVE | CVE-2021-29455 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-19 19:15:00 UTC |
| Updated | 2021-04-28 13:49:00 UTC |
| Description | Grassroot Platform is an application to make it faster, cheaper and easier to persistently organize and mobilize people in low-income communities. Grassroot Platform before master deployment as of 2021-04-16 did not properly verify the signature of JSON Web Tokens when refreshing an existing JWT. This allows to forge a valid JWT. The problem has been patched in version 1.3.1 by deprecating the JWT refresh function, which was an overdue deprecation regardless (the "refresh" flow is no longer used). |
Risk And Classification
Problem Types: CWE-347
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Grassroot | Grassroot Platform | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Merge pull request #412 from grassrootza/fix/refresh · grassrootza/grassroot-platform@a2e6e88 · GitHub | MISC | github.com | |
| GitHub - grassrootza/grassroot-platform: Modular application to make it easier and faster to organize and mobilize people, through a meeting organizer, vote taker, action logger and group manager. | MISC | github.com | |
| Missing validation of JWT signature in `grassrootza/grassroot-platform` · Advisory · grassrootza/grassroot-platform · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.