CVE-2024-33531: High severity cdbattags lua-resty-jwt vulnerability
Published Apr 24, 2024
·Updated
cdbattags lua-resty-jwt 0.2.3 allows attackers to bypass all JWT-parsing signature checks by crafting a JWT with an enc header with the value A256GCM.
Affected Software
2 affected components
cdbattags lua-resty-jwt
IBM Concert Software<=1.0.0-2.1.0
Event History
Apr 24, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Dec 22, 2025
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-33531?
CVE-2024-33531 has a high severity rating due to its potential to allow attackers to bypass JWT-parsing signature checks.
2
How do I fix CVE-2024-33531?
To fix CVE-2024-33531, upgrade to the latest version of the lua-resty-jwt library where the vulnerability has been patched.
3
What type of attack does CVE-2024-33531 facilitate?
CVE-2024-33531 facilitates authentication bypass attacks through crafted JWTs.
4
Which software is affected by CVE-2024-33531?
CVE-2024-33531 affects the cdbattags lua-resty-jwt library version 0.2.3.
5
How can attackers exploit CVE-2024-33531?
Attackers can exploit CVE-2024-33531 by creating a JWT with an enc header set to A256GCM, bypassing signature checks.