Executive brief
jsonwebtoken is a widely-used Node.js library for creating and verifying JSON Web Tokens (JWTs), which are used for authentication and authorization. Versions before 9.0.0 did not properly validate that the key type matches the signing algorithm, allowing applications to accidentally use weaker legacy key types (like DSA) with modern algorithms (like RS256), potentially bypassing security controls or accepting forged tokens.
Technical details
The jsonwebtoken library prior to version 9.0.0 fails to validate that the asymmetric key type is compatible with the specified signing algorithm during JWT verification. This allows misconfigured applications to use legacy, cryptographically weak key types (such as DSA) in combination with modern algorithms (e.g., RS256 for RSA), violating cryptographic best practices. An attacker with knowledge of a weak key or the ability to influence key selection could potentially forge or manipulate JWTs, compromising authentication systems that rely on this library. The issue requires prior misconfiguration by the application developer, not a network-based exploit. Version 9.0.0 adds strict validation of key type and algorithm combinations; applications requiring backwards compatibility with invalid combinations can set allowInvalidAsymmetricKeyTypes to true.
Affected products
- Auth0 jsonwebtoken <=8.5.1
Timeline
- 2022-12-22: disclosed
- 2022-12-22: patched: Version 9.0.0 released with key type and algorithm validation