QID 983751
QID 983751: Nodejs (npm) Security Update for jws (GHSA-gjcw-v447-2w7q)
Affected versions of the `jws` package allow users to select what algorithm the server will use to verify a provided JWT. A malicious actor can use this behaviour to arbitrarily modify the contents of a JWT while still passing verification. For the common use case of the JWT as a bearer token, the end result is a complete authentication bypass with minimal effort. ## Recommendation Update to version 3.0.0 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-gjcw-v447-2w7q for updates pertaining to this vulnerability.
Vendor References
- GHSA-gjcw-v447-2w7q -
github.com/advisories/GHSA-gjcw-v447-2w7q
CVEs related to QID 983751
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gjcw-v447-2w7q | jws |
|