CVE-2015-9235
Verification Bypass in jsonwebtoken
EPSS 37.5%
Description
Versions 4.2.1 and earlier of `jsonwebtoken` are affected by a verification bypass vulnerability. This is a result of weak validation of the JWT algorithm type, occuring when an attacker is allowed to arbitrarily specify the JWT algorithm. ## Recommendation Update to version 4.2.2 or later.
How to fix CVE-2015-9235
To remediate CVE-2015-9235, upgrade the affected package to a fixed version below.
- npm/jsonwebtoken—upgrade to 4.2.2 or later
Is CVE-2015-9235 being exploited?
Moderate — EPSS is 37.5%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 4.2.2