CRITICAL 9.1 Maven
Missing validation of JWT signature in `ManyDesigns/Portofino`
GHSA-6g3c-2mh5-7q6x · CVE-2021-29451
Published · Modified
Description
Impact
Portofino is an open source web development framework. Portofino before version 5.2.1 did not properly verify the signature of JSON Web Tokens.
This allows forging a valid JWT.
Patches
The issue will be patched in the upcoming 5.2.1 release.
For more information
If you have any questions or comments about this advisory:
- Open an issue in https://github.com/ManyDesigns/Portofino
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes