GHSA-r65j-6h5f-4f92
Dashboard / Vulnerabilities / GHSA-r65j-6h5f-4f92
Summary: Withdrawn: JJWT improperly generates signing keys
Details: ## Withdrawn Advisory This advisory has been withdrawn because it has been found to be disputed. Please see the issue [here](https://github.com/jwtk/jjwt/issues/930#issuecomment-2032699358) for more information. ## Original Description JJWT (aka Java JWT) through 0.12.5 ignores certain characters and thus a user might falsely conclude that they have a strong key. The impacted code is the setSigningKey() method within the DefaultJwtParser class and the signWith() method within the DefaultJwtBuilder class.
References: https://nvd.nist.gov/vuln/detail/CVE-2024-31033, https://github.com/jwtk/jjwt/issues/930#issuecomment-2032699358, https://github.com/2308652512/JJWT_BUG, https://github.com/jwtk/jjwt, https://github.com/jwtk/jjwt/blob/26948610fbef81eba867cbaad54b516d1874c70a/impl/src/main/java/io/jsonwebtoken/impl/DefaultJwtParserBuilder.java#L242, https://www.viralpatel.net/java-create-validate-jwt-token
Affected packages
Package
Name: io.jsonwebtoken:jjwt-impl
Purl: pkg:maven/io.jsonwebtoken/jjwt-impl
Affected ranges
Type: ECOSYSTEM
Events:
