Improper Check for Unusual or Exceptional Conditions in Connect2id Nimbus JOSE+JWT
Critical severity
GitHub Reviewed
Published
Oct 16, 2019
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Oct 15, 2019
Reviewed
Oct 16, 2019
Published to the GitHub Advisory Database
Oct 16, 2019
Last updated
Feb 1, 2023
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
References