Improper Verification of Cryptographic Signature in pac4j - CVE-2021-44878

 

Improper Verification of Cryptographic Signature in pac4j - CVE-2021-44878

Published: December 6, 2022


Vulnerability identifier: #VU69935
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-44878
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists if an OpenID Connect provider supports the "none" algorithm, then pac4j does not refuse it without an explicit configuration on its side or for the "idtoken" response type. A remote attacker can bypass the token validation by injecting a malformed ID token using "none" as the value of "alg" key in the header with an empty signature value.


Affected software

pac4j
IBM Cloud Pak for Watson AIOps
Netcool Operations Insight

How to mitigate CVE-2021-44878

Install updates from vendor's website.

pac4j - update to 5.3.1
Netcool Operations Insight - update to 1.6.6

External References

Related Security Bulletins