CVE-2021-29500

HIGH

bubble_fireworks < 2021.BUILD-SNAPSHOT - Improper Verification of Cryptographic Signature

Title source: llm
STIX 2.1

Description

bubble fireworks is an open source java package relating to Spring Framework. In bubble fireworks before version 2021.BUILD-SNAPSHOT there is a vulnerability in which the package did not properly verify the signature of JSON Web Tokens. This allows to forgery of valid JWTs.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0060
EPSS Percentile 43.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-347
Status published
Products (1)
bubble_fireworks_project/bubble_fireworks < 2021.build-snapshot
Published Jun 04, 2021
Tracked Since Feb 18, 2026