Feed/CVE-2022-23529
CVE-2022-23529CRITICALCVSS 9.6

jsonwebtoken — Insecure JWT Secret Handling

Published Dec 21, 2022·Updated Dec 21, 2022

NVD Description

jsonwebtoken before 9.0.0 can be bypassed by a malicious actor if the secretOrPublicKey can be controlled. An attacker could forge a JWT token and pass verification when the key can be set to an object with a toString function.

Affected Packages (1)

jsonwebtokenNPM
Fixed in 9.0.0

Public Exploits & PoCs3 found

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free