Lucene search

K
cvelistMitreCVELIST:CVE-2020-26160
HistorySep 30, 2020 - 12:57 p.m.

CVE-2020-26160

2020-09-3012:57:10
mitre
www.cve.org
2

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

57.0%

jwt-go before 4.0.0-preview1 allows attackers to bypass intended access restrictions in situations with []string{} for m[โ€œaudโ€] (which is allowed by the specification). Because the type assertion fails, โ€œโ€ is the value of aud. This is a security problem if the JWT token is presented to a service that lacks its own audience check.

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

57.0%