Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-23928
HistoryFeb 01, 2023 - 1:15 a.m.

Authorization

2023-02-0101:15:00
PRIOn knowledge base
www.prio-n.com
2
reasonml ocaml jose
authorization bypass
security vulnerability
patched issue

9.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

51.1%

reason-jose is a JOSE implementation in ReasonML and OCaml.Jose.Jws.validate does not check HS256 signatures. This allows tampering of JWS header and payload data if the service does not perform additional checks. Such tampering could expose applications using reason-jose to authorization bypass. Applications relying on JWS claims assertion to enforce security boundaries may be vulnerable to privilege escalation. This issue has been patched in version 0.8.2.

CPENameOperatorVersion
reason-joselt0.8.2

9.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

51.1%

Related for PRION:CVE-2023-23928