joserfc is vulnerable to Improper Verification of Cryptographic Signature
20
Low Risk
Affected versions of this package are vulnerable to improper serialization of token headers due to allowing unprotected headers to overwrite integrity-protected headers. An attacker with access to the JWS JSON object can exploit this by injecting malicious values into unprotected headers (e.g., modifying key to point to a malicious key, or altering exp to extend token validity), bypassing signature validation for critical parameters and potentially leading to authentication bypass or privilege escalation.
You are affected if you are using a version that falls within the vulnerable range.
joserfc is vulnerable to Improper Verification of Cryptographic Signature in versions 1.2.0 - 1.3.0.
Upgrade the joserfc library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant