Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2019-10-15 14:15
Updated : 2023-11-07 03:06
NVD link : CVE-2019-17195
Mitre link : CVE-2019-17195
CVE.ORG link : CVE-2019-17195
JSON object : View
Products Affected
apache
- hadoop
oracle
- insurance_policy_administration
- jd_edwards_enterpriseone_orchestrator
- policy_automation
- data_integrator
- enterprise_manager_base_platform
- healthcare_data_repository
- solaris_cluster
- weblogic_server
- communications_pricing_design_center
- peoplesoft_enterprise_peopletools
- jd_edwards_enterpriseone_tools
- primavera_gateway
- communications_cloud_native_core_security_edge_protection_proxy
connect2id
- nimbus_jose\+jwt
CWE
CWE-755
Improper Handling of Exceptional Conditions