JWT Signature Verification Bypass in NAMSHI | JOSE 5.0.0 and Earlier

JWT Signature Verification Bypass in NAMSHI | JOSE 5.0.0 and Earlier

CVE-2015-2964 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:P/A:N

NAMSHI | JOSE 5.0.0 and earlier allows remote attackers to bypass signature verification via crafted tokens in a JSON Web Tokens (JWT) header.

Learn more about our Web App Pen Testing.