nimble_zta is vulnerable to Improper Verification of Cryptographic Signature
92
Critical Risk
The nimble_zta Cloudflare authentication strategy accepts Zero Trust JWTs without checking whether JOSE.JWT.verify/2 reports the signature as valid. A crafted service token with the expected issuer and required claims is authenticated even when its cryptographic signature fails verification. Applications that enable the Cloudflare strategy can be impersonated by any party able to submit such a token. The fix checks the verification boolean before authenticating the JWT.
You are affected if you are using a version that falls within the vulnerable range and you use the Cloudflare authentication strategy.
nimble_zta is vulnerable to Improper Verification of Cryptographic Signature in versions 0.1.2 - 0.1.2.
Upgrade the nimble_zta library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.