漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
@fastify/jwt vulnerable to authorization bypass via global secret overriding the per-request key
Vulnerability Description
@fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verification key passed to request.jwtVerify({ key }) is silently overridden by the plugin's globally configured secret, because the option merge applies the global key last. Applications that use different keys for different authorization domains, for example separate user and admin keys, therefore accept a token signed with the global key on a route that explicitly requires another key. This lets an ordinary authenticated user cross a key-based trust boundary without knowing either secret. The issue is fixed in @fastify/jwt 10.2.2, where an explicit per-call key takes precedence over the global secret. Users should upgrade to 10.2.2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
密码学签名的验证不恰当
Vulnerability Title
Fastify @fastify/jwt 加密问题漏洞
Vulnerability Description
Fastify @fastify/jwt是Fastify组织的一个JWT认证库。 Fastify @fastify/jwt 10.2.2之前版本存在加密问题漏洞,该漏洞源于请求验证密钥被插件全局配置的密钥覆盖,可能导致普通认证用户跨基于密钥的信任边界。
CVSS Information
N/A
Vulnerability Type
N/A