漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
inversoft prime-jwt version prior to commit abb0d479389a2509f939452a6767dc424bb5e6ba contains a CWE-20 vulnerability in JWTDecoder.decode that can result in an incorrect signature validation of a JWT token. This attack can be exploitable when an attacker crafts a JWT token with a valid header using 'none' as algorithm and a body to requests it be validated. This vulnerability was fixed after commit abb0d479389a2509f939452a6767dc424bb5e6ba.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
inversoft prime-jwt 输入验证漏洞
Vulnerability Description
inversoft prime-jwt是一个开源的基于Java 8的JWT库。 inversoft prime-jwt commit abb0d479389a2509f939452a6767dc424bb5e6ba之前版本中的JWTDecoder.decode存在输入验证漏洞,该漏洞源于JWTDecoder缺少输入验证。攻击者可利用该漏洞绕过JWT签名检测。
CVSS Information
N/A
Vulnerability Type
N/A