CVE-2015-9235

CVE-2015-9235

Vendor Hackerone
Product jsonwebtoken node module
Weakness CWE-20 · Input validation
Published May 29, 2018
Last update September 16, 2024

CVSS base score

What the vulnerability does

01Description

In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but instead the attacker send a token digitally signed with a symmetric algorithm (HS* family).

Key dates

02Disclosure timeline

May 29, 2018 CVE published
September 16, 2024 Record updated