Search

Contact Us

Log in

Vulnerabilities / Using jwk parameter to verify JWTs

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Severity
high
CWE NameUsing jwk parameter to verify JWTs
CWE IDCWE-345
CWE Score7.5
Compliance
OWASP TOP10 -> A8
ISO 27001 -> A.8.2, A.8.3, A.8.5, A.8.24
HIPAA -> 164.306(a), 164.312(c)(1)
CVSS3.0
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
Confidentiality ImpactNone
Integrity ImpactHigh
Availability ImpactNone
Using jwk parameter to verify JWTs