Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27284
HistorySep 30, 2020 - 12:55 a.m.

Authorization Bypass

2020-09-3000:55:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.002 Low

EPSS

Percentile

57.0%

github.com/dgrijalva/jwt-go is vulnerable to authorization bypass. The vulnerability exists as the audience verification succeeds even if the type assertion fails when the value of aud is "".