Authentication Bypass in Try Mode Affecting hapi-auth-jwt2 package, versions <5.1.2
Threat Intelligence
EPSS
0.32% (71st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID npm:hapi-auth-jwt2:20160128
- published 28 Jan 2016
- disclosed 28 Jan 2016
- credit Alan Shaw
Introduced: 28 Jan 2016
CVE-2016-10525 Open this link in a new tabHow to fix?
Upgrade to version 5.1.2 or greater.
Overview
Authentication bypass issues exist in hapi-auth-jwt2
version 5.1.1, when try
authentication mode is used, request.auth.isAuthenticated
will be set to true
for unauthenticated users.
CVSS Scores
version 3.1