ZÉROJOUR

The zero-day paper — printed from structured content, not scraped prose.
Permanent editionPublic dataset · Sanity GROQGHSA × CISA KEV
jsonwebtoken (npm) · published 2022-12-22

jsonwebtoken unrestricted key type could lead to legacy keys usage

CVE-2022-23539 — CVSS 8.1/10. Fix: upgrade to 9.0.0.
Package
jsonwebtoken
Ecosystem
npm
Vector
NETWORK
Complexity
LOW
Privileges
LOW
Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Overview

Versions `<=8.5.1` of `jsonwebtoken` library could be misconfigured so that legacy, insecure key types are used for signature verification. For example, DSA keys could be used with the RS256 algorithm.

Am I affected?

You are affected if you are using an algorithm and a key type other than the combinations mentioned below

| Key type | algorithm |

|----------|------------------------------------------|

| ec | ES256, ES384, ES512 |

| rsa | RS256, RS384, RS512, PS256, PS384, PS512 |

| rsa-pss | PS256, PS384, PS512 |

And for Elliptic Curve algorithms:

| `alg` | Curve |

|-------|------------|

Weakness classes: CWE-327 (Use of a Broken or Risky Cryptographic Algorithm)

Source: GHSA-8cf7-32gw-wr33 · GitHub Advisory Database (CC-BY-4.0) — printed from a structured Sanity dataset. ← Back to the front page

ZéroJour prints itself from a Sanity dataset of real advisories (GitHub Advisory Database, CC-BY-4.0; CISA KEV). No scraping, no keyword search — headlines are typed fields, scores are numbers, fixes are versions. The newsroom composes, a human approves.