Vulnerability Details CVE-2024-37568
lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (This is similar to CVE-2022-29217 and CVE-2024-33663.)
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.6%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2024-37568
-
cpe:2.3:a:authlib:authlib:-
-
cpe:2.3:a:authlib:authlib:0.1
-
cpe:2.3:a:authlib:authlib:0.10
-
cpe:2.3:a:authlib:authlib:0.11
-
cpe:2.3:a:authlib:authlib:0.12
-
cpe:2.3:a:authlib:authlib:0.12.1
-
cpe:2.3:a:authlib:authlib:0.13
-
cpe:2.3:a:authlib:authlib:0.14
-
cpe:2.3:a:authlib:authlib:0.14.1
-
cpe:2.3:a:authlib:authlib:0.14.2
-
cpe:2.3:a:authlib:authlib:0.14.3
-
cpe:2.3:a:authlib:authlib:0.15
-
cpe:2.3:a:authlib:authlib:0.15.1
-
cpe:2.3:a:authlib:authlib:0.15.2
-
cpe:2.3:a:authlib:authlib:0.15.3
-
cpe:2.3:a:authlib:authlib:0.15.4
-
cpe:2.3:a:authlib:authlib:0.15.5
-
cpe:2.3:a:authlib:authlib:0.15.6
-
cpe:2.3:a:authlib:authlib:0.2
-
cpe:2.3:a:authlib:authlib:0.2.1
-
cpe:2.3:a:authlib:authlib:0.3
-
cpe:2.3:a:authlib:authlib:0.4
-
cpe:2.3:a:authlib:authlib:0.4.1
-
cpe:2.3:a:authlib:authlib:0.5
-
cpe:2.3:a:authlib:authlib:0.5.1
-
cpe:2.3:a:authlib:authlib:0.6
-
cpe:2.3:a:authlib:authlib:0.7
-
cpe:2.3:a:authlib:authlib:0.8
-
cpe:2.3:a:authlib:authlib:0.9
-
cpe:2.3:a:authlib:authlib:1.0.0
-
cpe:2.3:a:authlib:authlib:1.0.1
-
cpe:2.3:a:authlib:authlib:1.1.0
-
cpe:2.3:a:authlib:authlib:1.2.0
-
cpe:2.3:a:authlib:authlib:1.2.1
-
cpe:2.3:a:authlib:authlib:1.3.0