Improper Input Validation Affecting lcobucci/jwt package, versions >=4.1.0, <4.1.5>=4.0.0-alpha1, <4.0.4<3.4.6


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.21% (11th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-LCOBUCCIJWT-1726912
  • published29 Sept 2021
  • disclosed29 Sept 2021
  • creditAnton Smirnov

Introduced: 29 Sep 2021

CVE-2021-41106  (opens in a new tab)
CWE-345  (opens in a new tab)

How to fix?

Upgrade lcobucci/jwt to version 4.1.5, 4.0.4, 3.4.6 or higher.

Overview

lcobucci/jwt is a simple library to work with JSON Web Token and JSON Web Signature.

Affected versions of this package are vulnerable to Improper Input Validation. Users of HMAC-based algorithms (HS256, HS384, and HS512) combined with Lcobucci\JWT\Signer\Key\LocalFileReference as key are having their tokens issued and validated using the file path as the hashing key instead of the file contents. This behaviour is misleading.

CVSS Base Scores

version 3.1