jsjws@0.6.0 vulnerabilities

Wraps jsrsasign (http://kjur.github.io/jsrsasign/) and uses Node crypto routines for performance

  • latest version

    6.0.3

  • latest non vulnerable version

  • first published

    11 years ago

  • latest version published

    4 years ago

  • deprecated

    Package is deprecated

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the jsjws package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Authentication Bypass

    The jsjws is a pure JavaScript implementation of JSON Web Signature. JSON Web Tokens are an open, industry standard method for representing claims securely between two parties.

    Affected versions of this module treated tokens signed with the none algorithm as a valid token with a verified signature and resulted in giving attackers arbitrary account access.

    How to fix Authentication Bypass?

    Upgrade jsjws to version 2.0.0 or higher.

    <2.0.0