CVE-2019-17195
published 2019-10-15CVE-2019-17195: Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential…
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
11.03%
95.4th percentile
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | hadoop | — | — |
| connect2id | nimbus_jose_+jwt | < 7.9 | 7.9 |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | — | — |
| oracle | communications_pricing_design_center | — | — |
| oracle | data_integrator | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | healthcare_data_repository | — | — |
| oracle | insurance_policy_administration | 11.0 – 11.3.1 | — |
| oracle | jd_edwards_enterpriseone_orchestrator | <= 9.2.5.3 | — |
| oracle | jd_edwards_enterpriseone_tools | <= 9.2.5.3 | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | policy_automation | 12.2.0 – 12.2.22 | — |
| oracle | primavera_gateway | — | — |
| oracle | primavera_gateway | 18.8.0 – 18.8.11 | — |
| oracle | solaris_cluster | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: WLS Configuration Template (Nimbus JOSE+JWT) — CVE-2019-17195
vendor_oracle·2022-10-15·CVSS 9.8
CVE-2019-17195 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: WLS Configuration Template (Nimbus JOSE+JWT) — CVE-2019-17195
Oracle Oracle Fusion Middleware Risk Matrix: WLS Configuration Template (Nimbus JOSE+JWT) vulnerability
CVE: CVE-2019-17195
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Systems Risk Matrix: Tools (Nimbus JOSE+JWT) — CVE-2019-17195
vendor_oracle·2022-04-15·CVSS 9.8
CVE-2019-17195 [CRITICAL] Oracle Oracle Systems Risk Matrix: Tools (Nimbus JOSE+JWT) — CVE-2019-17195
Oracle Oracle Systems Risk Matrix: Tools (Nimbus JOSE+JWT) vulnerability
CVE: CVE-2019-17195
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Health Sciences Applications Risk Matrix: Install Utility (Nimbus JOSE+JWT) — CVE-2019-17195
vendor_oracle·2021-10-15·CVSS 9.8
CVE-2019-17195 [CRITICAL] Oracle Oracle Health Sciences Applications Risk Matrix: Install Utility (Nimbus JOSE+JWT) — CVE-2019-17195
Oracle Oracle Health Sciences Applications Risk Matrix: Install Utility (Nimbus JOSE+JWT) vulnerability
CVE: CVE-2019-17195
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Communications Applications Risk Matrix: CNE (Nimbus JOSE+JWT) — CVE-2019-17195
vendor_oracle·2021-07-15·CVSS 9.8
CVE-2019-17195 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: CNE (Nimbus JOSE+JWT) — CVE-2019-17195
Oracle Oracle Communications Applications Risk Matrix: CNE (Nimbus JOSE+JWT) vulnerability
CVE: CVE-2019-17195
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Enterprise Manager Install (Nimbus JOSE+JWT) — CVE-2019-17195
vendor_oracle·2021-04-15·CVSS 9.8
CVE-2019-17195 [CRITICAL] Oracle Oracle Enterprise Manager Risk Matrix: Enterprise Manager Install (Nimbus JOSE+JWT) — CVE-2019-17195
Oracle Oracle Enterprise Manager Risk Matrix: Enterprise Manager Install (Nimbus JOSE+JWT) vulnerability
CVE: CVE-2019-17195
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Core Components (Connect2id Nimbus JOSE+JWT) — CVE-2019-17195
vendor_oracle·2021-01-15·CVSS 9.8
CVE-2019-17195 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Core Components (Connect2id Nimbus JOSE+JWT) — CVE-2019-17195
Oracle Oracle Fusion Middleware Risk Matrix: Core Components (Connect2id Nimbus JOSE+JWT) vulnerability
CVE: CVE-2019-17195
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Admin (Connect2id Nimbus JOSE+JWT) — CVE-2019-17195
vendor_oracle·2020-04-15·CVSS 9.8
CVE-2019-17195 [CRITICAL] Oracle Oracle Construction and Engineering Risk Matrix: Admin (Connect2id Nimbus JOSE+JWT) — CVE-2019-17195
Oracle Oracle Construction and Engineering Risk Matrix: Admin (Connect2id Nimbus JOSE+JWT) vulnerability
CVE: CVE-2019-17195
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Red Hat
nimbus-jose-jwt: Uncaught exceptions while parsing a JWT
vendor_redhat·2019-10-15·CVSS 9.8
CVE-2019-17195 [CRITICAL] CWE-248 nimbus-jose-jwt: Uncaught exceptions while parsing a JWT
nimbus-jose-jwt: Uncaught exceptions while parsing a JWT
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
A flaw was found in Connect2id Nimbus JOSE+JWT prior to version 7.9. While processing JSON web tokens (JWT), nimbus-jose-jwt can throw various uncaught exceptions resulting in an application crash, information disclosure, or authentication bypass. The highest threat from this vulnerability is to data confidentiality and system availability.
Statement: In Red Hat Virtualization 4.2, nimbus-jose-jwt was bundled in the rhvm-dependencies package. In Red Hat Virtualization 4.3, nimbus-jose-jwt was made available as a separate
OSV
Improper Check for Unusual or Exceptional Conditions in Connect2id Nimbus JOSE+JWT
osv·2019-10-16
CVE-2019-17195 [CRITICAL] Improper Check for Unusual or Exceptional Conditions in Connect2id Nimbus JOSE+JWT
Improper Check for Unusual or Exceptional Conditions in Connect2id Nimbus JOSE+JWT
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
GHSA
Improper Check for Unusual or Exceptional Conditions in Connect2id Nimbus JOSE+JWT
ghsa·2019-10-16
CVE-2019-17195 [CRITICAL] CWE-754 Improper Check for Unusual or Exceptional Conditions in Connect2id Nimbus JOSE+JWT
Improper Check for Unusual or Exceptional Conditions in Connect2id Nimbus JOSE+JWT
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-17195 nimbus-jose-jwt: Uncaught exceptions while parsing a JWT
bugzilla·2019-10-23·CVSS 9.8
CVE-2019-17195 [CRITICAL] CVE-2019-17195 nimbus-jose-jwt: Uncaught exceptions while parsing a JWT
CVE-2019-17195 nimbus-jose-jwt: Uncaught exceptions while parsing a JWT
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
References:
https://connect2id.com/blog/nimbus-jose-jwt-7-9
https://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/SECURITY-CHANGELOG.txt
Discussion:
Created nimbus-jose-jwt tracking bugs for this issue:
Affects: fedora-all [bug 1764792]
---
Note: latest version is 8.2, compared to 5.12 a new dependency is needed:
[WARNING] The POM for com.google.crypto.tink:tink:jar:1.2.2 is missing, no dependency information available
I'll try to understand how difficult will be getting thie new dependency pack
Bugzilla
CVE-2019-17195 nimbus-jose-jwt: Uncaught exceptions while parsing a JWT [fedora-all]
bugzilla·2019-10-23·CVSS 9.8
CVE-2019-17195 [CRITICAL] CVE-2019-17195 nimbus-jose-jwt: Uncaught exceptions while parsing a JWT [fedora-all]
CVE-2019-17195 nimbus-jose-jwt: Uncaught exceptions while parsing a JWT [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Tenable
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
blogs_tenable·2022-10-19
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle April 2021 Critical Patch Update Addresses 257 CVEs including ‘Zerologon’ (CVE-2020-1472)
blogs_tenable·2021-04-21·CVSS 5.5
[MEDIUM] Oracle April 2021 Critical Patch Update Addresses 257 CVEs including ‘Zerologon’ (CVE-2020-1472)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
https://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/SECURITY-CHANGELOG.txthttps://connect2id.com/blog/nimbus-jose-jwt-7-9https://lists.apache.org/thread.html/8768553cda5838f59ee3865cac546e824fa740e82d9dc2a7fc44e80d%40%3Ccommon-dev.hadoop.apache.org%3Ehttps://lists.apache.org/thread.html/e10d43984f39327e443e875adcd4a5049193a7c010e81971908caf41%40%3Ccommon-issues.hadoop.apache.org%3Ehttps://lists.apache.org/thread.html/r2667286c8ceffaf893b16829b9612d8f7c4ee6b30362c6c1b583e3c2%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r33dc233634aedb04fa77db3eb79ea12d15ca4da89fa46a1c585ecb0b%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r35f6301a3e6a56259224786dd9c2a935ba27ff6b494d15a3b66efe6a%40%3Cdev.avro.apache.org%3Ehttps://lists.apache.org/thread.html/r5e08837e695efd36be73510ce58ec05785dbcea077819d8acc2d990d%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rcac26c2d4df22341fa6ebbfe93ba1eff77d2dcd3f6106a1dc1f9ac98%40%3Cdev.avro.apache.org%3Ehttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/SECURITY-CHANGELOG.txthttps://connect2id.com/blog/nimbus-jose-jwt-7-9https://lists.apache.org/thread.html/8768553cda5838f59ee3865cac546e824fa740e82d9dc2a7fc44e80d%40%3Ccommon-dev.hadoop.apache.org%3Ehttps://lists.apache.org/thread.html/e10d43984f39327e443e875adcd4a5049193a7c010e81971908caf41%40%3Ccommon-issues.hadoop.apache.org%3Ehttps://lists.apache.org/thread.html/r2667286c8ceffaf893b16829b9612d8f7c4ee6b30362c6c1b583e3c2%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r33dc233634aedb04fa77db3eb79ea12d15ca4da89fa46a1c585ecb0b%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r35f6301a3e6a56259224786dd9c2a935ba27ff6b494d15a3b66efe6a%40%3Cdev.avro.apache.org%3Ehttps://lists.apache.org/thread.html/r5e08837e695efd36be73510ce58ec05785dbcea077819d8acc2d990d%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rcac26c2d4df22341fa6ebbfe93ba1eff77d2dcd3f6106a1dc1f9ac98%40%3Cdev.avro.apache.org%3Ehttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2019-10-15
Published