jwt is vulnerable to Insufficient Verification of Data Authenticity
20
Low Risk
Affected versions of this package contain a design flaw that can lead to unverified JWT claims, allowing attackers to bypass authentication by tampering with the token payload and presenting malicious JWTs that may be accepted without proper claim validation, potentially leading to unauthorized access or privilege escalation.
You are affected if you are using a version that falls within the vulnerable range.
jwt is vulnerable to Insufficient Verification of Data Authenticity in versions 0.0.1 - 3.0.0.
Upgrade the jwt library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant