Vulnerability Details CVE-2018-1000531
inversoft prime-jwt version prior to commit abb0d479389a2509f939452a6767dc424bb5e6ba contains a CWE-20 vulnerability in JWTDecoder.decode that can result in an incorrect signature validation of a JWT token. This attack can be exploitable when an attacker crafts a JWT token with a valid header using 'none' as algorithm and a body to requests it be validated. This vulnerability was fixed after commit abb0d479389a2509f939452a6767dc424bb5e6ba.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 62.6%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2018-1000531
-
cpe:2.3:a:inversoft:prime-jwt:0.1.0
-
cpe:2.3:a:inversoft:prime-jwt:0.1.1
-
cpe:2.3:a:inversoft:prime-jwt:0.1.2
-
cpe:2.3:a:inversoft:prime-jwt:0.1.3
-
cpe:2.3:a:inversoft:prime-jwt:0.1.4
-
cpe:2.3:a:inversoft:prime-jwt:0.1.5
-
cpe:2.3:a:inversoft:prime-jwt:0.1.6
-
cpe:2.3:a:inversoft:prime-jwt:0.2.0
-
cpe:2.3:a:inversoft:prime-jwt:0.2.1
-
cpe:2.3:a:inversoft:prime-jwt:1.0.0
-
cpe:2.3:a:inversoft:prime-jwt:1.1.0
-
cpe:2.3:a:inversoft:prime-jwt:1.2.0
-
cpe:2.3:a:inversoft:prime-jwt:1.2.1
-
cpe:2.3:a:inversoft:prime-jwt:1.3.0