Vulnerability CVE-2019-17195


Published: 2019-10-15

Description:
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.

 References:
https://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/SECURITY-CHANGELOG.txt
https://connect2id.com/blog/nimbus-jose-jwt-7-9

Copyright 2024, cxsecurity.com

 

Back to Top