CVE-2019-17195

Severity
9.8CRITICAL
EPSS
3.0%
top 13.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 15
Latest updateOct 15

Description

Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages16 packages

Patches

🔴Vulnerability Details

3
OSV
Improper Check for Unusual or Exceptional Conditions in Connect2id Nimbus JOSE+JWT2019-10-16
GHSA
Improper Check for Unusual or Exceptional Conditions in Connect2id Nimbus JOSE+JWT2019-10-16
CVEList
CVE-2019-17195: Connect2id Nimbus JOSE+JWT before v72019-10-15

📋Vendor Advisories

8
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: WLS Configuration Template (Nimbus JOSE+JWT) — CVE-2019-171952022-10-15
Oracle
Oracle Oracle Systems Risk Matrix: Tools (Nimbus JOSE+JWT) — CVE-2019-171952022-04-15
Oracle
Oracle Oracle Health Sciences Applications Risk Matrix: Install Utility (Nimbus JOSE+JWT) — CVE-2019-171952021-10-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: CNE (Nimbus JOSE+JWT) — CVE-2019-171952021-07-15
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Enterprise Manager Install (Nimbus JOSE+JWT) — CVE-2019-171952021-04-15

💬Community

2
Bugzilla
CVE-2019-17195 nimbus-jose-jwt: Uncaught exceptions while parsing a JWT2019-10-23
Bugzilla
CVE-2019-17195 nimbus-jose-jwt: Uncaught exceptions while parsing a JWT [fedora-all]2019-10-23