Miggo Logo

CVE-2022-25898: JWS and JWT signature validation vulnerability with special characters

8.6

CVSS Score
3.1

Basic Information

EPSS Score
0.56207%
Published
6/25/2022
Updated
1/27/2023
KEV Status
No
Technology
TechnologyJavaScript

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
jsrsasignnpm>= 4.8.0, < 10.5.2510.5.25

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Imp**t Jsrs*si*n supports JWS(JSON W** Si*n*tur*s) *n* JWT(JSON W** Tok*n) v*li**tion. *ow*v*r JWS or JWT si*n*tur* wit* non **s***URL *n*o*in* sp**i*l ***r**t*rs or num**r *s**p** ***r**t*rs m*y ** v*li**t** *s v*li* *y mist*k*. *or *x*mpl*, *

Reasoning

No *n*lysis *v*il**l*