CVE-2017-18239
Exposure of Sensitive information in authentikat-jwt
9.8
CRITICAL
CVSS 3.1
EPSS 0.40%
Description
A time-sensitive equality check on the JWT signature in the JsonWebToken.validate method in main/scala/authentikat/jwt/JsonWebToken.scala in authentikat-jwt (aka com.jason-goodwin/authentikat-jwt) version 0.4.5 and earlier allows the supplier of a JWT token to guess bit after bit of the signature by repeating validation requests.
How to fix CVE-2017-18239
To remediate CVE-2017-18239, upgrade the affected package to a fixed version below.
- —upgrade to 0.4.6 or later
Is CVE-2017-18239 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.4.6
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |