CVE-2016-10555
MEDIUM 6.5EPSS 4.9%
Since "algorithm" isn't enforced in jwt.decode()in jwt-simple 0.3.0 and earlier, a malicious user could choose what algorithm is sent sent to the server. If the server is expecting RSA but is sent HMAC-SHA with RSA's public key, the server will think the public key is actually an HMAC private key. This could be used to forge any data an attacker wants.
- CVSS v3.0
- 6.5 MEDIUM
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N - CVSS v2.0
- 4.0 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N - EPSS
- 4.90% chance of exploitation in the next 30 days, 91th percentile
- Published
- 2018-05-31
- Updated
- 2024-09-16
Proof-of-concept exploits (3)
- CircuitSoul/poc-cve-2016-105551★ · 2021-06-14
- FroydCod3r/poc-cve-2016-105551★ · 2021-06-14
- scent2d/PoC-CVE-2016-105550★ · 2022-01-03