CVE-2020-28042
MEDIUMServicestack < 5.9.2 - Signature Verification Bypass
Title source: ruleDescription
ServiceStack before 5.9.2 mishandles JWT signature verification unless an application has a custom ValidateToken function that establishes a valid minimum length for a signature.
Exploits (1)
Scores
CVSS v3
5.3
EPSS
0.3599
EPSS Percentile
97.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Classification
CWE
CWE-347
Status
published
Affected Products (2)
servicestack/servicestack
< 5.9.2
nuget/ServiceStack
< 5.9.2NuGet
Timeline
Published
Nov 02, 2020
Tracked Since
Feb 18, 2026