Skip to content

Missing signature validation of JWT when alg=none

High
UBaggeler published GHSA-5m5q-3qw2-3xf3 Jul 30, 2020

Package

maven org.dpppt.backend.sdk.ws (Maven)

Affected versions

< 1.1.1

Patched versions

1.1.1

Description

Impact

When dp3t-sdk-backend is configured to check a JWT before uploading/publishing keys, it was possible to skip the signature check by providing a JWT token with "alg":"none".

Patches

The issue has been patched in version 1.1.1.

References

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2020-15957

Weaknesses

No CWEs

Credits