Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
07 Nov 2023, 03:06
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2019-10-15 14:15
Updated : 2024-02-28 17:28
NVD link : CVE-2019-17195
Mitre link : CVE-2019-17195
CVE.ORG link : CVE-2019-17195
JSON object : View
Products Affected
oracle
- communications_cloud_native_core_security_edge_protection_proxy
- healthcare_data_repository
- weblogic_server
- jd_edwards_enterpriseone_orchestrator
- enterprise_manager_base_platform
- peoplesoft_enterprise_peopletools
- primavera_gateway
- insurance_policy_administration
- policy_automation
- communications_pricing_design_center
- jd_edwards_enterpriseone_tools
- solaris_cluster
- data_integrator
connect2id
- nimbus_jose\+jwt
apache
- hadoop
CWE
CWE-755
Improper Handling of Exceptional Conditions