Vulnerability CVE-2024-33531


Published: 2024-04-24

Description:
cdbattags lua-resty-jwt 0.2.3 allows attackers to bypass all JWT-parsing signature checks by crafting a JWT with an enc header with the value A256GCM.

 References:
https://insinuator.net/2023/10/lua-resty-jwt-authentication-bypass/
https://github.com/cdbattags/lua-resty-jwt/issues/61
https://github.com/cdbattags/lua-resty-jwt/commit/d1558e2afefe868fea1e7e9a4b04ea94ab678a85

Copyright 2024, cxsecurity.com

 

Back to Top