CVE-2019-17195: Critical severity ibm pub vulnerability
A flaw was found in Connect2id Nimbus JOSE+JWT prior to version 7.9. While processing JSON web tokens (JWT), nimbus-jose-jwt can throw various uncaught exceptions resulting in an application crash, information disclosure, or authentication bypass. The highest threat from this vulnerability is to data confidentiality and system availability.
Other sources
Connect2id Nimbus JOSE+JWT is vulnerable to a denial of service, caused by the throwing of various uncaught exceptions while parsing a JWT. An attacker could exploit this vulnerability to crash the application or obtain sensitive information.
— IBM
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-17195?
CVE-2019-17195 is a vulnerability found in Connect2id Nimbus JOSE+JWT prior to version 7.9.
What is the severity of CVE-2019-17195?
The severity of CVE-2019-17195 is critical with a CVSS score of 9.8.
How does CVE-2019-17195 affect Connect2id Nimbus JOSE+JWT?
CVE-2019-17195 can result in an application crash, information disclosure, or authentication bypass.
How can I fix CVE-2019-17195?
To fix CVE-2019-17195, update Connect2id Nimbus JOSE+JWT to version 7.9.
Where can I find more information about CVE-2019-17195?
You can find more information about CVE-2019-17195 at the following references: [link1], [link2], [link3].