Input validation error in Nimbus JOSE+JWT - CVE-2019-17195

 

Input validation error in Nimbus JOSE+JWT - CVE-2019-17195

Published: January 9, 2020 / Updated: February 6, 2020


Vulnerability identifier: #VU24168
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-17195
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to Nimbus JOSE+JWT throws various uncaught exceptions while parsing a JWT. A remote attacker can send a specially crafted JWT token and cause the application to crash or potentially bypass authentication.


Affected software

Nimbus JOSE+JWT
ovirt-fast-forward-upgrade (Red Hat package)
apache-commons-beanutils (Red Hat package)
ovirt-engine (Red Hat package)
ovirt-engine-extension-aaa-misc (Red Hat package)
hadoop-debugsource
hadoop-common
hadoop-client
hadoop-maven-plugin
hadoop-mapreduce
hadoop-mapreduce-examples
hadoop-tests
hadoop-yarn
hadoop-httpfs
hadoop-yarn-security
hadoop-common-native
libhdfs
hadoop-devel
hadoop-debuginfo
hadoop
hadoop-hdfs
rhvm-dependencies (Red Hat package)
IBM PureData System for Operational Analytics
Enterprise Manager Base Platform
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Solaris Cluster
openEuler
Red Hat Virtualization
Red Hat Virtualization Manager
DataStage on Cloud Pak for Data
IBM Engineering Requirements Management DOORS Next
Oracle Policy Automation
Oracle Data Integrator
Robotic Process Automation for Cloud Pak
Spring Security
PeopleSoft Enterprise PeopleTools
JD Edwards EnterpriseOne Orchestrator
JD Edwards EnterpriseOne Tools
Oracle Communications Pricing Design Center
Oracle WebLogic Server
Primavera Gateway
RSA Authentication Manager

How to mitigate CVE-2019-17195

Install updates from vendor's website.

Nimbus JOSE+JWT - update to 7.9
ovirt-fast-forward-upgrade (Red Hat package) - update to 1.0.0-17.el7ev
apache-commons-beanutils (Red Hat package) - update to 1.8.3-15.el7_7
ovirt-engine (Red Hat package) - update to 4.3.9.3-0.1.el7
DataStage on Cloud Pak for Data - update to 4.8.5
Spring Security - addressed in versions 5.2.2, 5.3.0
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
ovirt-engine-extension-aaa-misc (Red Hat package) - update to 1.0.4-1.el7ev
hadoop-debugsource - update to 3.2.1-10
hadoop-common - update to 3.2.1-10
hadoop-client - update to 3.2.1-10
hadoop-maven-plugin - update to 3.2.1-10
hadoop-mapreduce - update to 3.2.1-10
hadoop-mapreduce-examples - update to 3.2.1-10
hadoop-tests - update to 3.2.1-10
hadoop-yarn - update to 3.2.1-10
hadoop-httpfs - update to 3.2.1-10
hadoop-yarn-security - update to 3.2.1-10
hadoop-common-native - update to 3.2.1-10
libhdfs - update to 3.2.1-10
hadoop-devel - update to 3.2.1-10
hadoop-debuginfo - update to 3.2.1-10
hadoop - update to 3.2.1-10
hadoop-hdfs - update to 3.2.1-10
rhvm-dependencies (Red Hat package) - update to 4.3.2-1.el7ev
RSA Authentication Manager - addressed in versions 8.4 Patch 11, 8.5 Patch 3
Robotic Process Automation for Cloud Pak - update to 21.0.7

External References

Related Security Bulletins