[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2020-26160 -- golang-github-dgrijalva-jwt-go

Deprecated
ID: oval:org.secpod.oval:def:2003963Date: (C)2020-10-08   (M)2023-02-07
Class: VULNERABILITYFamily: unix




jwt-go before 4.0.0-preview1 allows attackers to bypass intended access restrictions in situations with []string{} for m["aud"] . Because the type assertion fails, "" is the value of aud. This is a security problem if the JWT token is presented to a service that lacks its own audience check.

Platform:
Debian 10.x
Debian 9.x
Product:
golang-github-dgrijalva-jwt-go-dev
Reference:
CVE-2020-26160
CVE    1
CVE-2020-26160
CPE    3
cpe:/o:debian:debian_linux:10.x
cpe:/a:github:golang-github-dgrijalva-jwt-go-dev
cpe:/o:debian:debian_linux:9.x

© SecPod Technologies