Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34867
HistoryMar 30, 2022 - 6:13 a.m.

Validation Bypass

2022-03-3006:13:21
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
50
validation bypass
firebase/php-jwt
jwt.php
key ring
server-side validations

EPSS

0.001

Percentile

46.0%

firebase/php-jwt is vulnerable to validation bypass. The vulnerability exists in decode and verify functions in JWT.php because the token validations are not properly handled when multiple keys are loaded in a key ring which allows an attacker to bypass server-side validations.

EPSS

0.001

Percentile

46.0%