CVE-2019-17195
CRITICALConnect2id Nimbus JOSE+JWT < 7.9 - Denial of Service and Authentication Bypass via JWT Parsing
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-17195. PoCs published by somatrasss.
AI-analyzed exploit summary This repository contains a Python script to scan for multiple WebLogic vulnerabilities, including CVE-2020-14756. The script checks for unauthenticated access to a specific path to determine vulnerability.
Description
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
Exploits (1)
This repository contains a Python script to scan for multiple WebLogic vulnerabilities, including CVE-2020-14756. The script checks for unauthenticated access to a specific path to determine vulnerability.
References (16)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H