Lucene search

K
osvGoogleOSV:GO-2020-0017
HistoryApr 14, 2021 - 8:04 p.m.

Authorization bypass in github.com/dgrijalva/jwt-go

2021-04-1420:04:52
Google
osv.dev
18

7.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

57.0%

If a JWT contains an audience claim with an array of strings, rather than a single string, and MapClaims.VerifyAudience is called with req set to false, then audience verification will be bypassed, allowing an invalid set of audiences to be provided.

7.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

57.0%