A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens using a key that is embedded within the token
Published Jan 4, 2018
7.5
HIGHCVSS 3.1
EPSS 42.65%
Description
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens using a key that is embedded within the token. The vulnerability is due to node-jose following the JSON Web Signature (JWS) standard for JSON Web Tokens (JWTs). This standard specifies that a JSON Web Key (JWK) representing a public key can be embedded within the header of a JWS. This public key is then trusted for verification. An attacker could exploit this by forging valid JWS objects by removing the original signature, adding a new public key to the header, and then signing the object using the (attacker-owned) private key associated with the public key embedded in that JWS header.
Affected products
- Vendor n/a Product Node-jose Library Defaultn/a
- Version Node-jose LibraryStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Node-jose Library | n/a |
|
No data.
No Red Hat product state for this CVE.
node-jose
npm
Introduced 0 Fixed 0.11.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | node-jose | 0 | 0.11.0 |
Remediation
No remediation recorded yet.
References (8)
- http://www.securityfocus.com/bid/102445 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://github.com/advisories/GHSA-jfxm-w8g2-4rcv Advisory
- https://github.com/cisco/node-jose/blob/master/CHANGELOG.md x_refsource_CONFIRMRelease NotesThird Party Advisory
- https://github.com/zi0Black/POC-CVE-2018-0114 x_refsource_MISCExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-0114
- https://tools.cisco.com/security/center/viewAlert.x?alertId=56326 x_refsource_CONFIRMPatchVendor Advisory
- https://web.archive.org/web/20210124130907/http://www.securityfocus.com/bid/102445
- https://www.exploit-db.com/exploits/44324/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/102445 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://github.com/advisories/GHSA-jfxm-w8g2-4rcv | Advisory | |
| https://github.com/cisco/node-jose/blob/master/CHANGELOG.md | x_refsource_CONFIRMRelease NotesThird Party Advisory | |
| https://github.com/zi0Black/POC-CVE-2018-0114 | x_refsource_MISCExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-0114 | ||
| https://tools.cisco.com/security/center/viewAlert.x?alertId=56326 | x_refsource_CONFIRMPatchVendor Advisory | |
| https://web.archive.org/web/20210124130907/http://www.securityfocus.com/bid/102445 | ||
| https://www.exploit-db.com/exploits/44324/ | exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.