Skip to content

Missing validation of JWT signature in `ManyDesigns/Portofino`

High
alessiostalla published GHSA-6g3c-2mh5-7q6x Apr 16, 2021

Package

maven com.manydesigns.portofino (Maven)

Affected versions

>= 5.0.0, < 5.2.1

Patched versions

5.2.1

Description

Impact

https://github.com/ManyDesigns/Portofino before version 5.2.1 did not properly verify the signature of JSON Web Tokens.
This allows forging a valid JWT.

Patches

The issue will be patched in the upcoming 5.2.1 release.

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2021-29451

Weaknesses

No CWEs

Credits