Loading vulnerability details...
An improper signature verification vulnerability exists when using auth0/node-jws with the HS256 algorithm under specific conditions.
You are affected by this vulnerability if you meet all of the following preconditions:
You are NOT affected by this vulnerability if you meet any of the following preconditions:
auth0/node-jsonwebtoken users fall into this category and are therefore NOT affected by this vulnerability)Upgrade auth0/node-jws version to version 3.2.3 or 4.0.1
Okta would like to thank Félix Charette for discovering this vulnerability.
An improper signature verification vulnerability exists when using auth0/node-jws with the HS256 algorithm under specific conditions.
You are affected by this vulnerability if you meet all of the following preconditions:
You are NOT affected by this vulnerability if you meet any of the following preconditions:
auth0/node-jsonwebtoken users fall into this category and are therefore NOT affected by this vulnerability)Upgrade auth0/node-jws version to version 3.2.3 or 4.0.1
Okta would like to thank Félix Charette for discovering this vulnerability.
This high-severity vulnerability could allow attackers to gain unauthorized access, execute arbitrary code, or compromise data integrity. Prompt remediation is strongly recommended.
Probability of exploitation in the next 30 days · more likely than 11.0% of all CVEs.
Apply security patches to version 3.2.3, 4.0.1 immediately
Isolate affected systems from untrusted networks until patching is complete
Implement enhanced monitoring for exploitation attempts and unusual behavior