Connect2id Nimbus JOSE+JWT 代码问题漏洞

admin 2024-01-13 21:05:50 YS 来源:ZONE.CI 全球网 0 阅读模式
> Connect2id Nimbus JOSE+JWT 代码问题漏洞

Connect2id Nimbus JOSE+JWT 代码问题漏洞

CNNVD-ID编号 CNNVD-201910-914 CVE编号 CVE-2019-17195
发布时间 2019-10-15 更新时间 2021-01-27
漏洞类型 代码问题 漏洞来源 N/A
危险等级 超危 威胁类型 远程
厂商 N/A

漏洞介绍

Connect2id Nimbus JOSE+JWT是Connect2id公司的一款基于Java的开源JWT(JSON Web Tokens)实现。

Connect2id Nimbus JOSE+JWT 7.9之前版本中存在代码问题漏洞。该漏洞源于网络系统或产品的代码开发过程中存在设计或实现不当的问题。

漏洞补丁

目前厂商已发布升级了Connect2id Nimbus JOSE+JWT 代码问题漏洞的补丁,Connect2id Nimbus JOSE+JWT 代码问题漏洞的补丁获取链接:

参考网址

来源:connect2id.com

链接:https://connect2id.com/blog/nimbus-jose-jwt-7-9

来源:bitbucket.org

链接:https://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/SECURITY-CHANGELOG.txt

来源:MLIST

链接:https://lists.apache.org/thread.html/8768553cda5838f59ee3865cac546e824fa740e82d9dc2a7fc44e80d@%3Ccommon-dev.hadoop.apache.org%3E

来源:N/A

链接:https://www.oracle.com/security-alerts/cpuapr2020.html

来源:MISC

链接:https://www.oracle.com/security-alerts/cpujan2021.html

来源:MLIST

链接:https://lists.apache.org/thread.html/e10d43984f39327e443e875adcd4a5049193a7c010e81971908caf41@%3Ccommon-issues.hadoop.apache.org%3E

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-dependent-libraries-affect-ibm-db2-leading-to-denial-of-service-or-privilege-escalation-2/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-have-been-identified-in-db2-that-affect-the-ibm-performance-management-product/

来源:www.oracle.com

链接:https://www.oracle.com/security-alerts/cpujan2021.html

来源:vigilance.fr

链接:https://vigilance.fr/vulnerability/Connect2id-Nimbus-JOSE-JWT-privilege-escalation-via-JWT-Parsing-31843

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-dependent-libraries-affect-ibm-db2-leading-to-denial-of-service-or-privilege-escalation/

来源:nvd.nist.gov

链接:https://nvd.nist.gov/vuln/detail/CVE-2019-17195

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.1427/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.1193/

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/157073/Red-Hat-Security-Advisory-2020-1308-01.html

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/158750/Red-Hat-Security-Advisory-2020-3247-01.html

受影响实体

暂无

信息来源

http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201910-914

weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
评论:0   参与:  0