GO-2020-0017
Dashboard / Vulnerabilities / GO-2020-0017
Summary: Authorization bypass in github.com/dgrijalva/jwt-go
Details: If a JWT contains an audience claim with an array of strings, rather than a single string, and MapClaims.VerifyAudience is called with req set to false, then audience verification will be bypassed, allowing an invalid set of audiences to be provided.
References: https://github.com/dgrijalva/jwt-go/commit/ec0a89a131e3e8567adcb21254a5cd20a70ea4ab, https://github.com/dgrijalva/jwt-go/issues/422
Affected packages
Package
Name: github.com/dgrijalva/jwt-go
Purl: pkg:golang/github.com/dgrijalva/jwt-go
Affected ranges
Type: SEMVER
Events:
Introduced- 0.0.0-20150717181359-44718f8a89b0
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
