Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35701
HistoryMay 25, 2022 - 7:35 a.m.

Authentication Bypass

2022-05-2507:35:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
51

0.001 Low

EPSS

Percentile

45.7%

pyjwt is vulnerable to authentication bypass. The vulnerability exists because the library permits an attacker submitting a JWT token to choose which algorithms are used when signing in, enabling non-blocklisted, but weak public key formats to be supported in the authentication process allowing an attacker to perform unauthorized actions.