CVE-2022-39227
Python-jwt subject to Authentication Bypass by Spoofing
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key. Depending on the application, this may for example enable the attacker to spoof other user's identities, hijack their sessions, or bypass authentication. Users should upgrade to version 3.3.4. There are no known workarounds.
python-jwt es un módulo para generar y verificar tokens web JSON. Las versiones anteriores a 3.3.4, están sujetas a Una Omisión de la Autenticación por medio de Suplantación, resultando en una suplantación de identidad, secuestro de la sesión o omisión de autenticación. Un atacante que obtiene un JWT puede falsificar arbitrariamente su contenido sin conocer la clave secreta. Dependiendo de la aplicación, esto puede permitir al atacante, por ejemplo, falsificar la identidad de otros usuarios, secuestrar sus sesiones o omitir la autenticación. Los usuarios deben actualizar a versión 3.3.4. No se presentan mitigaciones conocidas.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2022-09-02 CVE Reserved
- 2022-09-23 CVE Published
- 2024-03-19 First Exploit
- 2024-07-11 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-290: Authentication Bypass by Spoofing
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://github.com/pypa/advisory-database/blob/main/vulns/python-jwt/PYSEC-2022-259.yaml | Third Party Advisory | |
https://www.vicarius.io/vsociety/posts/authentication-bypass-in-python-jwt |
URL | Date | SRC |
---|---|---|
https://github.com/user0x1337/CVE-2022-39227 | 2024-03-19 | |
https://github.com/NoSpaceAvailable/CVE-2022-39227 | 2024-03-28 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Python-jwt Project Search vendor "Python-jwt Project" | Python-jwt Search vendor "Python-jwt Project" for product "Python-jwt" | >= 3.0.0 < 3.3.4 Search vendor "Python-jwt Project" for product "Python-jwt" and version " >= 3.0.0 < 3.3.4" | - |
Affected
|