CVE-2015-2964: Input Validation
Published Jul 5, 2015
·Updated
NAMSHI | JOSE 5.0.0 and earlier allows remote attackers to bypass signature verification via crafted tokens in a JSON Web Tokens (JWT) header.
Affected Software
1 affected component
NAMSHI Namshi\/jose<=5.0.0
Event History
Jul 5, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2964?
CVE-2015-2964 has a moderate severity rating due to the potential for signature verification bypass leading to unauthorized access.
2
How do I fix CVE-2015-2964?
To fix CVE-2015-2964, upgrade to a version later than 5.0.0 of the Namshi JOSE library.
3
Who is affected by CVE-2015-2964?
CVE-2015-2964 affects all versions of Namshi JOSE up to and including 5.0.0.
4
What types of attacks can exploit CVE-2015-2964?
CVE-2015-2964 can be exploited by remote attackers to bypass JWT signature verification through crafted tokens.
5
Is CVE-2015-2964 being actively exploited in the wild?
At the time of discovery, there were indications that CVE-2015-2964 could be actively exploited, necessitating prompt mitigation.