Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Information regarding Algorithm Confusion Vulnerability #27

Open
SCH227 opened this issue Oct 16, 2024 · 0 comments
Open

Information regarding Algorithm Confusion Vulnerability #27

SCH227 opened this issue Oct 16, 2024 · 0 comments

Comments

@SCH227
Copy link

SCH227 commented Oct 16, 2024

Hello! Thanks for this awesome project.

I was reading this issue in the authlib repo that describes the Algorithm Confusion Vulnerability CVE-2024-37568. Quoting the firsts lines:

If the algorithm field is left unspecified when calling jwt.decode, the library will allow HMAC verification with ANY asymmetric public key. The library does no checks whatsoever to mitigate this. This applies to verification with the algorithms HS256, HS384, and HS512 in lieu of the asymmetric algorithm. This issue is also persistent in joserfc.

However, I did not find any information about the vulnerability in this repo.
Is joserfc vulnerable to Algorithm Confusion? Which versions are affected? Was the issue fixed?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant