Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2019-10-15 07:15
Updated : 2022-06-07 11:40
NVD link : CVE-2019-17195
Mitre link : CVE-2019-17195
JSON object : View
CWE
CWE-755
Improper Handling of Exceptional Conditions
Products Affected
oracle
- weblogic_server
- communications_pricing_design_center
- policy_automation
- communications_cloud_native_core_security_edge_protection_proxy
- insurance_policy_administration
- data_integrator
- healthcare_data_repository
- jd_edwards_enterpriseone_orchestrator
- peoplesoft_enterprise_peopletools
- primavera_gateway
- enterprise_manager_base_platform
- jd_edwards_enterpriseone_tools
- solaris_cluster
connect2id
- nimbus_jose\+jwt
apache
- hadoop