Executive brief
The jsonwebtoken library, a popular tool for handling secure digital tokens in Node.js applications, contains a flaw in how it validates security keys. If an application is configured to allow untrusted users to influence the key used for verification, an attacker could potentially execute malicious code or write unauthorized files on the server. This could lead to a full system compromise, though it requires the application to be using the library in a specific, non-standard way.
Technical details
A vulnerability in the `jwt.verify()` function of the `jsonwebtoken` library (versions <= 8.5.1) stems from insufficient validation of the `secretOrPublicKey` argument. If an attacker can control this parameter, they may be able to trigger remote code execution (RCE) or arbitrary file writes on the host machine. This is classified as an insecure input validation issue (CWE-20). While originally assigned CVE-2022-23529, the CVE was later retracted because exploitation requires the calling application to pass untrusted input directly into the key retrieval parameter, which is considered an insecure implementation pattern rather than a flaw in the library's default behavior. The issue is mitigated in version 9.0.0 by introducing stricter asymmetric key type validations.
Affected products
- Auth0 jsonwebtoken <= 8.5.1
Timeline
- 2022-12-21: patched: Version 9.0.0 released
- 2022-12-22: disclosed
- 2023-01-27: other: CVE-2022-23529 was retracted after further review