Junglewise Threat Intelligence

gree jose signature bypass via none algorithm

Severity: critical · CVSS 9.8 · Published 2024-05-15

Technologies: gree/jose (Packagist), Gree Jose. Vendors: Packagist.

Executive brief

The gree/jose library, used for handling JSON Web Tokens (JWT) in PHP applications, contains a flaw that allows attackers to bypass security checks. By using a specially crafted token that specifies no encryption (the "none" algorithm), an attacker can impersonate other users or gain unauthorized access to sensitive data. This could lead to full account takeover or unauthorized operations within the affected application.

Technical details

The gree/jose library is vulnerable to a signature bypass due to improper verification of the 'none' algorithm in JSON Web Tokens (JWT). When a token is presented with the 'alg' header set to 'none', the library may treat the token as valid without verifying a cryptographic signature. This allows a remote, unauthenticated attacker to forge tokens with arbitrary payloads, such as elevated privileges or different user identities, by simply removing the signature and updating the header. The vulnerability is rooted in the improper implementation of CWE-347 and CWE-327. The issue is addressed in version 2.2.1.

Affected products

  • gree jose < 2.2.1

Timeline

  • 2024-05-15: advisory: GitHub Advisory published
  • 2024-05-15: patched: Fix identified in version 2.2.1

References

Related threats