jsjws@0.7.4 vulnerabilities

Wraps jsrsasign (http://kjur.github.io/jsrsasign/) and uses Node crypto routines for performance

Direct Vulnerabilities

Known vulnerabilities in the jsjws package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Authentication Bypass

The jsjws is a pure JavaScript implementation of JSON Web Signature. JSON Web Tokens are an open, industry standard method for representing claims securely between two parties.

Affected versions of this module treated tokens signed with the none algorithm as a valid token with a verified signature and resulted in giving attackers arbitrary account access.

How to fix Authentication Bypass?

Upgrade jsjws to version 2.0.0 or higher.

<2.0.0