Aller au contenu

Fiche vulnérabilité

CVE-2022-39227 : faille critique python-jwt project python-jwt (CVSS 9.1)

Description

python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key. Depending on the application, this may for example enable the attacker to spoof other user's identities, hijack their sessions, or bypass authentication. Users should upgrade to version 3.3.4. There are no known workarounds.

En bref

Sévérité
Critique (CVSS 9.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
23 sept. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • python-jwt project python-jwt

Références

Rechercher une autre vulnérabilité dans la base CVE