QID 981339
QID 981339: Java (maven) Security Update for com.jason-goodwin:authentikat-jwt_2.12 (GHSA-3rhm-67j6-42jq)
A time-sensitive equality check on the JWT signature in the JsonWebToken.validate method in main/scala/authentikat/jwt/JsonWebToken.scala in authentikat-jwt (aka com.jason-goodwin/authentikat-jwt) version 0.4.5 and earlier allows the supplier of a JWT token to guess bit after bit of the signature by repeating validation requests.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-3rhm-67j6-42jq for updates pertaining to this vulnerability.
Vendor References
- GHSA-3rhm-67j6-42jq -
github.com/advisories/GHSA-3rhm-67j6-42jq
CVEs related to QID 981339
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3rhm-67j6-42jq | com.jason-goodwin:authentikat-jwt_2.12 |
|