VOOZH about

URL: https://nvd.nist.gov/vuln/detail/CVE-2022-23529

⇱ NVD - CVE-2022-23529


  1. Vulnerabilities

CVE-2022-23529 Detail

Rejected

This CVE has been marked Rejected in the CVE List. These CVEs are stored in the NVD, but do not show up in search results by default.

Current Description

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The issue is not a vulnerability. Notes: none.


View Analysis Description

Analysis Description

node-jsonwebtoken is a JsonWebToken implementation for node.js. For versions `<= 8.5.1` of `jsonwebtoken` library, if a malicious actor has the ability to modify the key retrieval parameter (referring to the `secretOrPublicKey` argument from the readme link of the `jwt.verify()` function, they can write arbitrary files on the host machine. Users are affected only if untrusted entities are allowed to modify the key retrieval parameter of the `jwt.verify()` on a host that you control. This issue has been fixed, please update to version 9.0.0.

Metrics

NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 4.0 Severity and Vector Strings:

NVD assessment not yet provided.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected].

URL Source(s) Tag(s)

Weakness Enumeration

CWE-ID CWE Name Source

Change History

4 change records found show changes

CVE Modified by GitHub, Inc. 11/06/2023 10:44:12 PM

Action Type Old Value New Value
Changed Description
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The issue is not a vulnerability. Notes: none.


Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The issue is not a vulnerability. Notes: none.


CVE Modified by GitHub, Inc. 1/27/2023 5:15:08 PM

Action Type Old Value New Value
Changed Description
node-jsonwebtoken is a JsonWebToken implementation for node.js. For versions `<= 8.5.1` of `jsonwebtoken` library, if a malicious actor has the ability to modify the key retrieval parameter (referring to the `secretOrPublicKey` argument from the readme link of the `jwt.verify()` function, they can write arbitrary files on the host machine. Users are affected only if untrusted entities are allowed to modify the key retrieval parameter of the `jwt.verify()` on a host that you control. This issue has been fixed, please update to version 9.0.0.


** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The issue is not a vulnerability. Notes: none.


Removed CVSS V3.1
GitHub, Inc. AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L


Removed CWE
GitHub, Inc. CWE-20


Removed Reference
https://github.com/auth0/node-jsonwebtoken/commit/e1fa9dcc12054a8681db4e6373da1b30cf7016e3 [Patch, Third Party Advisory]


Removed Reference
https://github.com/auth0/node-jsonwebtoken/security/advisories/GHSA-27h2-hvpr-p74q [Third Party Advisory]


Removed CVSS V3.1 Reason
A-No limiting factors


Removed CVSS V3.1 Reason
C-No limiting factors


Removed CVSS V3.1 Reason
PR-No privileges needed


CVE Rejected by GitHub, Inc. 1/27/2023 5:15:08 PM

Action Type Old Value New Value

Initial Analysis by NIST 12/30/2022 4:50:33 PM

Action Type Old Value New Value
Added CVSS V3.1
NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H


Added CPE Configuration
OR
 *cpe:2.3:a:auth0:jsonwebtoken:*:*:*:*:*:node.js:*:* versions up to (including) 8.5.1


Changed Reference Type
https://github.com/auth0/node-jsonwebtoken/commit/e1fa9dcc12054a8681db4e6373da1b30cf7016e3 No Types Assigned


https://github.com/auth0/node-jsonwebtoken/commit/e1fa9dcc12054a8681db4e6373da1b30cf7016e3 Patch, Third Party Advisory


Changed Reference Type
https://github.com/auth0/node-jsonwebtoken/security/advisories/GHSA-27h2-hvpr-p74q No Types Assigned


https://github.com/auth0/node-jsonwebtoken/security/advisories/GHSA-27h2-hvpr-p74q Third Party Advisory


Quick Info

CVE Dictionary Entry:
CVE-2022-23529
NVD Published Date:
12/21/2022
NVD Last Modified:
11/06/2023
Source:
GitHub, Inc.