Improper Authentication in lua-resty-jwt - CVE-2024-33531
Published: September 19, 2024 / Updated: April 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests. A remote attacker can bypass authentication process and gain unauthorized access to the application by sending a specially crafted JWT with an enc header with the value A256GCM.
Affected software
Cloud Pak for Data
How to mitigate CVE-2024-33531
Cloud Pak for Data - update to 4.8.5