CVE-2023-23928
Last modified
CVE-2023-23928 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. reason-jose is a JOSE implementation in ReasonML and OCaml.`Jose.Jws.validate` does not check HS256 signatures. This allows tampering of JWS header and payload data if the service does not perform additional checks. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
reason-jose is a JOSE implementation in ReasonML and OCaml.`Jose.Jws.validate` does not check HS256 signatures. This allows tampering of JWS header and payload data if the service does not perform additional checks. Such tampering could expose applications using reason-jose to authorization bypass. Applications relying on JWS claims assertion to enforce security boundaries may be vulnerable to privilege escalation. This issue has been patched in version 0.8.2.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Reason-Jose Project | Reason-Jose | < 0.8.2 |
References
- https://github.com/ulrikstrid/reason-jose/commit/36cd724db3cbec121757624da49072386bd869e5Patch, Third Party Advisory
- https://github.com/ulrikstrid/reason-jose/releases/tag/v0.8.2Release Notes, Third Party Advisory
- https://github.com/ulrikstrid/reason-jose/commit/36cd724db3cbec121757624da49072386bd869e5Patch, Third Party Advisory
- https://github.com/ulrikstrid/reason-jose/releases/tag/v0.8.2Release Notes, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-23928?
How severe is CVE-2023-23928?
How do I fix CVE-2023-23928?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-23922The vulnerability was found Moodle which exists due to insuf…6.1
- CVE-2023-23923The vulnerability was found Moodle which exists due to insuf…8.2
- CVE-2023-23924Dompdf is an HTML to PDF converter. The URI validation on do…9.8
- CVE-2023-23925Switcher Client is a JavaScript SDK to work with Switcher AP…7.5
- CVE-2023-23926APOC (Awesome Procedures on Cypher) is an add-on library for…8.1
- CVE-2023-23927Craft is a platform for creating digital experiences. When y…5.4
- CVE-2023-23929vantage6 is a privacy preserving federated learning infrastr…8.8
- CVE-2023-2393A vulnerability was found in Netgear SRX5308 up to 4.3.5-3. …4.8
- CVE-2023-23930vantage6 is privacy preserving federated learning infrastruc…7.2
- CVE-2023-23931cryptography is a package designed to expose cryptographic p…6.5
- CVE-2023-23932OpenDDS is an open source C++ implementation of the Object M…7.5
- CVE-2023-23933OpenSearch Anomaly Detection identifies atypical data and re…4.3
Are you affected by CVE-2023-23928?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
