Skip to content

Missing validation of JWT signature in `fxbin/bubble-fireworks`

High
fxbin published GHSA-hj36-84cp-29pr May 21, 2021

Package

No package listed

Affected versions

<2021.BUILD-SNAPSHOT

Patched versions

2021.BUILD-SNAPSHOT

Description

Impact

What kind of vulnerability is it? Who is impacted?,
https://github.com/fxbin/bubble-fireworks before version XXX did not properly verify the signature of JSON Web Tokens.
This allows to forge a valid JWT.

Patches

Has the problem been patched? What versions should users upgrade to?

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2021-29500

Weaknesses

No CWEs

Credits