Lucene search

K
ibmIBM549E7C0F847035771C3248CFF939686D82680412D47CFB4143AD25D71DC7EAB2
HistoryFeb 02, 2022 - 4:08 p.m.

Security Bulletin: IBM Security Guardium Insights is affected by JWT-Go vulnerability (CVE-2020-26160)

2022-02-0216:08:31
www.ibm.com
11

0.002 Low

EPSS

Percentile

57.0%

Summary

IBM Security Guardium Insights adreesed the following issue

Vulnerability Details

CVEID:CVE-2020-26160
**DESCRIPTION:**jwt-go could allow a remote attacker to bypass security restrictions, caused by a type assertion failure when m[โ€œaudโ€] happens to be []string{}. By sending a specially-crafted request, an attacker could exploit this vulnerability to bypass access restrictions.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/189408 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Security Guardium Insights 3.0.1

Remediation/Fixes


Product

|

VRMF

|

Remediation / Fix

โ€”|โ€”|โ€”
IBM Security Guardium Insights| 3.0.1|

Please download version 3.1

https://www.ibm.com/software/passportadvantage/?mhsrc=ibmsearch_a&mhq=pasport%20advantage

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm security guardiumeq3.0.1

0.002 Low

EPSS

Percentile

57.0%

Related for 549E7C0F847035771C3248CFF939686D82680412D47CFB4143AD25D71DC7EAB2