Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about NULL Pointer Dereference vulnerabilities in an interactive lesson.
Start learningA fix was pushed into the master branch but not yet published.
Affected versions of this package are vulnerable to NULL Pointer Dereference in the JwksFetcherImpl. An attacker can cause a crash by sending requests with multiple JWT tokens, triggering a re-entry bug that leads to a null pointer dereference when the asynchronous HTTP response arrives.
allow_missing_or_failed or allow_missingNotes:
allow_missing_or_failed or allow_missing is enabled.