CVE-2018-0114

HIGH

Cisco Node-jose < 0.11.0 - Signature Verification Bypass

Title source: rule

Description

A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens using a key that is embedded within the token. The vulnerability is due to node-jose following the JSON Web Signature (JWS) standard for JSON Web Tokens (JWTs). This standard specifies that a JSON Web Key (JWK) representing a public key can be embedded within the header of a JWS. This public key is then trusted for verification. An attacker could exploit this by forging valid JWS objects by removing the original signature, adding a new public key to the header, and then signing the object using the (attacker-owned) private key associated with the public key embedded in that JWS header.

Exploits (15)

exploitdb WORKING POC
by zioBlack · pythonwebappsmultiple
https://www.exploit-db.com/exploits/44324
nomisec WORKING POC 282 stars
by z-bool · poc
https://github.com/z-bool/Venom-JWT
nomisec WORKING POC 25 stars
by zi0Black · poc
https://github.com/zi0Black/POC-CVE-2018-0114
nomisec WRITEUP 4 stars
by j4k0m · poc
https://github.com/j4k0m/CVE-2018-0114
nomisec WORKING POC 3 stars
by scumdestroy · poc
https://github.com/scumdestroy/CVE-2018-0114
nomisec WORKING POC 2 stars
by Eremiel · poc
https://github.com/Eremiel/CVE-2018-0114
nomisec WORKING POC 1 stars
by fevra-dev · poc
https://github.com/fevra-dev/ClaimJumper
nomisec WORKING POC 1 stars
by adityathebe · poc
https://github.com/adityathebe/POC-CVE-2018-0114
nomisec WORKING POC
by sealldeveloper · poc
https://github.com/sealldeveloper/CVE-2018-0114-PoC
nomisec WORKING POC
by n0m-d · poc
https://github.com/n0m-d/CVE-2018-0114-Go
nomisec WORKING POC
by amr9k8 · poc
https://github.com/amr9k8/jwt-spoof-tool
nomisec WORKING POC
by Pandora-research · poc
https://github.com/Pandora-research/CVE-2018-0114-Exploit
nomisec WORKING POC
by mmeza-developer · poc
https://github.com/mmeza-developer/CVE-2018-0114
nomisec WORKING POC
by Starry-lord · poc
https://github.com/Starry-lord/CVE-2018-0114
nomisec WORKING POC
by Logeirs · poc
https://github.com/Logeirs/CVE-2018-0114

Scores

CVSS v3 7.5
EPSS 0.8488
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-347
Status published
Products (2)
cisco/node-jose < 0.11.0
npm/node-jose 0 - 0.11.0npm
Published Jan 04, 2018
Tracked Since Feb 18, 2026