Input validation error in Nimbus JOSE+JWT - CVE-2019-17195
Published: January 9, 2020 / Updated: February 6, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to Nimbus JOSE+JWT throws various uncaught exceptions while parsing a JWT. A remote attacker can send a specially crafted JWT token and cause the application to crash or potentially bypass authentication.
Affected software
ovirt-fast-forward-upgrade (Red Hat package)
apache-commons-beanutils (Red Hat package)
ovirt-engine (Red Hat package)
ovirt-engine-extension-aaa-misc (Red Hat package)
hadoop-debugsource
hadoop-common
hadoop-client
hadoop-maven-plugin
hadoop-mapreduce
hadoop-mapreduce-examples
hadoop-tests
hadoop-yarn
hadoop-httpfs
hadoop-yarn-security
hadoop-common-native
libhdfs
hadoop-devel
hadoop-debuginfo
hadoop
hadoop-hdfs
rhvm-dependencies (Red Hat package)
IBM PureData System for Operational Analytics
Enterprise Manager Base Platform
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Solaris Cluster
openEuler
Red Hat Virtualization
Red Hat Virtualization Manager
DataStage on Cloud Pak for Data
IBM Engineering Requirements Management DOORS Next
Oracle Policy Automation
Oracle Data Integrator
Robotic Process Automation for Cloud Pak
Spring Security
PeopleSoft Enterprise PeopleTools
JD Edwards EnterpriseOne Orchestrator
JD Edwards EnterpriseOne Tools
Oracle Communications Pricing Design Center
Oracle WebLogic Server
Primavera Gateway
RSA Authentication Manager
How to mitigate CVE-2019-17195
ovirt-fast-forward-upgrade (Red Hat package) - update to 1.0.0-17.el7ev
apache-commons-beanutils (Red Hat package) - update to 1.8.3-15.el7_7
ovirt-engine (Red Hat package) - update to 4.3.9.3-0.1.el7
DataStage on Cloud Pak for Data - update to 4.8.5
Spring Security - addressed in versions 5.2.2, 5.3.0
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
ovirt-engine-extension-aaa-misc (Red Hat package) - update to 1.0.4-1.el7ev
hadoop-debugsource - update to 3.2.1-10
hadoop-common - update to 3.2.1-10
hadoop-client - update to 3.2.1-10
hadoop-maven-plugin - update to 3.2.1-10
hadoop-mapreduce - update to 3.2.1-10
hadoop-mapreduce-examples - update to 3.2.1-10
hadoop-tests - update to 3.2.1-10
hadoop-yarn - update to 3.2.1-10
hadoop-httpfs - update to 3.2.1-10
hadoop-yarn-security - update to 3.2.1-10
hadoop-common-native - update to 3.2.1-10
libhdfs - update to 3.2.1-10
hadoop-devel - update to 3.2.1-10
hadoop-debuginfo - update to 3.2.1-10
hadoop - update to 3.2.1-10
hadoop-hdfs - update to 3.2.1-10
rhvm-dependencies (Red Hat package) - update to 4.3.2-1.el7ev
RSA Authentication Manager - addressed in versions 8.4 Patch 11, 8.5 Patch 3
Robotic Process Automation for Cloud Pak - update to 21.0.7
External References
- https://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/SECURITY-CHANGELOG.txt
- https://connect2id.com/blog/nimbus-jose-jwt-7-9
- https://lists.apache.org/thread.html/8768553cda5838f59ee3865cac546e824fa740e82d9dc2a7fc44e80d@%3Ccommon-dev.hadoop.apache.org%3E
- https://lists.apache.org/thread.html/e10d43984f39327e443e875adcd4a5049193a7c010e81971908caf41@%3Ccommon-issues.hadoop.apache.org%3E
Related Security Bulletins
- Improper input validation in Connect2id Nimbus JOSE+JWT
- Denial of service due to usage of vulnerable Nimbus JOSE+JWT in Pivotal Spring Security
- Red Hat update for Red Hat Virtualization Engine
- Multiple vulnerabilities in Primavera Gateway
- Multiple vulnerabilities in Oracle WebLogic Server
- Multiple vulnerabilities in Enterprise Manager Base Platform
- Multiple vulnerabilities in Oracle Communications Pricing Design Center
- Input validation error in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in Primavera Gateway
- Multiple vulnerabilities in Oracle Data Integrator
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- Multiple vulnerabilities in JD Edwards EnterpriseOne Orchestrator
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Input validation error in Oracle Policy Automation
- Multiple vulnerabilities in Oracle Solaris Cluster
- Multiple vulnerabilities in IBM PureData System for Operational Analytics
- Multiple vulnerabilities in Oracle Data Integrator
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- openEuler 20.03 LTS SP1 update for hadoop
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data
- RSA Authentication Manager update for third-party components
- RSA Authentication Manager update for third-party components
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS and DOORS Web Access