Vulnerability Details CVE-2021-29500
bubble fireworks is an open source java package relating to Spring Framework. In bubble fireworks before version 2021.BUILD-SNAPSHOT there is a vulnerability in which the package did not properly verify the signature of JSON Web Tokens. This allows to forgery of valid JWTs.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 30.1%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2021-29500
-
cpe:2.3:a:bubble_fireworks_project:bubble_fireworks:0.0.3
-
cpe:2.3:a:bubble_fireworks_project:bubble_fireworks:0.0.4
-
cpe:2.3:a:bubble_fireworks_project:bubble_fireworks:0.0.5
-
cpe:2.3:a:bubble_fireworks_project:bubble_fireworks:0.0.6
-
cpe:2.3:a:bubble_fireworks_project:bubble_fireworks:0.0.7
-
cpe:2.3:a:bubble_fireworks_project:bubble_fireworks:0.0.8
-
cpe:2.3:a:bubble_fireworks_project:bubble_fireworks:0.0.9
-
cpe:2.3:a:bubble_fireworks_project:bubble_fireworks:1.0.0
-
cpe:2.3:a:bubble_fireworks_project:bubble_fireworks:1.0.1
-
cpe:2.3:a:bubble_fireworks_project:bubble_fireworks:2021.5