CVE Database
/

CVE-2015-9235

Back to search

CVE-2015-9235

Published: May 29, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but instead the attacker send a token digitally signed with a symmetric algorithm (HS* family).

VendorProductVersions

HackerOne

jsonwebtoken node module

affected
<4.2.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now