CRITICAL 9.1 Maven

Missing validation of JWT signature in `ManyDesigns/Portofino`

GHSA-6g3c-2mh5-7q6x · CVE-2021-29451

Published · Modified

Description

Impact

Portofino is an open source web development framework. Portofino before version 5.2.1 did not properly verify the signature of JSON Web Tokens.
This allows forging a valid JWT.

Patches

The issue will be patched in the upcoming 5.2.1 release.

For more information

If you have any questions or comments about this advisory:

Ready to move

Start Securing

Free, no credit card | First findings in minutes