In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but instead the attacker send a token digitally signed with a symmetric algorithm (HS* family).
PoC: CVE-2015-9235_JWT_key_confusion
automate CVE-2015-9235 exploitation
PoC: jwt-key-confusion-poc
JWT Key Confusion PoC (CVE-2015-9235) Written for the Hack the Box challenge - Under Construction
PoC: POC_CVE-2015-9235
Demo of the algorithm confusion attack on various JWT libraries
PoC: Venom-JWT
针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free