Wednesday, October 4, 2023
No Result
View All Result
Personal Safety News
  • Home
  • Domestic Violence
  • Crime
  • Personal Safety
  • Self Defense
  • Martial Arts
  • Bullying
  • More
    • Cyber Crimes
    • Stalking
    • Relationship Advice
    • MMA
Personal Safety News
  • Home
  • Domestic Violence
  • Crime
  • Personal Safety
  • Self Defense
  • Martial Arts
  • Bullying
  • More
    • Cyber Crimes
    • Stalking
    • Relationship Advice
    • MMA
Personal Safety News

Extreme Safety Flaw Present in “jsonwebtoken” Library Utilized by 22,000+ Tasks

by Personal Safety News
January 10, 2023
in Cyber Crimes
Reading Time: 2 mins read
247 5
A A
0
Home Cyber Crimes
Share on FacebookShare on Twitter


Jan 10, 2023Ravie LakshmananSoftware program Safety / Provide Chain

A high-severity safety flaw has been disclosed within the open supply jsonwebtoken (JWT) library that, if efficiently exploited, might result in distant code execution on a goal server.

“By exploiting this vulnerability, attackers might obtain distant code execution (RCE) on a server verifying a maliciously crafted JSON net token (JWT) request,” Palo Alto Networks Unit 42 researcher Artur Oleyarsh mentioned in a Monday report.

Tracked as CVE-2022-23529 (CVSS rating: 7.6), the problem impacts all variations of the library, together with and under 8.5.1, and has been addressed in model 9.0.0 shipped on December 21, 2022. The flaw was reported by the cybersecurity firm on July 13, 2022.

jsonwebtoken, which is developed and maintained by Okta’s Auth0, is a JavaScript module that permits customers to decode, confirm, and generate JSON net tokens as a method of securely transmitting info between two events for authorization and authentication. It has over 10 million weekly downloads on the npm software program registry and is utilized by greater than 22,000 initiatives.

Subsequently, the power to run malicious code on a server might break confidentiality and integrity ensures, doubtlessly enabling a foul actor to overwrite arbitrary recordsdata on the host and carry out any motion of their selecting utilizing a poisoned secret key.

high-severity security flaw

“With that being mentioned, so as to exploit the vulnerability described on this submit and management the secretOrPublicKey worth, an attacker might want to exploit a flaw inside the secret administration course of,” Oleyarsh defined.

As open supply software program more and more emerges as a profitable preliminary entry pathway for risk actors to stage provide chain assaults, it is essential that vulnerabilities in such instruments are proactively recognized, mitigated, and patched by downstream customers.

Making issues worse is the truth that cybercriminals have turn out to be a lot quicker at exploiting newly revealed flaws, drastically shrinking the time between a patch launch and exploit availability. In keeping with Microsoft, it solely takes 14 days on common for an exploit to be detected within the wild after public disclosure of a bug.

To fight this downside of vulnerability discovery, Google, final month, introduced the discharge of OSV-Scanner, an open supply utility that goals to determine all transitive dependencies of a mission and spotlight related shortcomings impacting it.

Discovered this text fascinating? Observe us on Twitter  and LinkedIn to learn extra unique content material we submit.



Source link

Tags: FlawjsonwebtokenLibraryProjectssecuritySevere
Share196Tweet123Share49Pin44Share34
Previous Post

Wooden vs Lara new date set for Feb 18 in Nottingham – Tickets

Next Post

The Marshall Challenge: Variety and Inclusion, 2022

Related Posts

Wing Disrupts the Market by Introducing Inexpensive SaaS Safety
Cyber Crimes

Wing Disrupts the Market by Introducing Inexpensive SaaS Safety

October 4, 2023
Linux Vulnerability Exposes Hundreds of thousands of Programs to Assault
Cyber Crimes

Linux Vulnerability Exposes Hundreds of thousands of Programs to Assault

October 4, 2023
Nexusflow Slots AI Into SOC Automation
Cyber Crimes

Nexusflow Slots AI Into SOC Automation

October 3, 2023
Scattered Spider Getting SaaS-y within the Cloud
Cyber Crimes

Scattered Spider Getting SaaS-y within the Cloud

October 2, 2023
Microsoft Defender Flags Tor Browser as Win32/Malgent!MTB Malware
Cyber Crimes

Microsoft Defender Flags Tor Browser as Win32/Malgent!MTB Malware

October 2, 2023
FBI Warns of Rising Development of Twin Ransomware Assaults Focusing on U.S. Corporations
Cyber Crimes

FBI Warns of Rising Development of Twin Ransomware Assaults Focusing on U.S. Corporations

September 30, 2023
Next Post
The Marshall Challenge: Variety and Inclusion, 2022

The Marshall Challenge: Variety and Inclusion, 2022

AMA—Anxiously Connected Particular person, Feelings and Males, Accepting Your Companion as They Are – Jayson and Ellen – 429

AMA—Anxiously Connected Particular person, Feelings and Males, Accepting Your Companion as They Are - Jayson and Ellen - 429

Q&A: Rob Rapley On His New PBS Doc and Demystifying The Lie Detector

Q&A: Rob Rapley On His New PBS Doc and Demystifying The Lie Detector

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Trending
  • Comments
  • Latest
Cigna Well being Knowledge Leak: 17 Billion Data Uncovered

Cigna Well being Knowledge Leak: 17 Billion Data Uncovered

September 1, 2023
Blood-stained mattresses faraway from Idaho house of murdered college students

Blood-stained mattresses faraway from Idaho house of murdered college students

January 7, 2023
Instagram influencers Racquelle Marie Dolores Anteola, Melissa Dufour caught with $3 million of cocaine: feds

Instagram influencers Racquelle Marie Dolores Anteola, Melissa Dufour caught with $3 million of cocaine: feds

June 11, 2023
Be taught essentially the most highly effective groin kick for self-defense.

Be taught essentially the most highly effective groin kick for self-defense.

May 31, 2023
Ebony Alert for lacking Black kids awaits Newsom’s OK

Ebony Alert for lacking Black kids awaits Newsom’s OK

September 16, 2023
Extracting Encrypted Credentials From Frequent Instruments

Extracting Encrypted Credentials From Frequent Instruments

December 29, 2022
Zuck doesn’t suck: Fb press launch denies Mark Zuckerberg received slept at BJJ match

Zuck doesn’t suck: Fb press launch denies Mark Zuckerberg received slept at BJJ match

June 4, 2023
Azure AD Token Forging Approach in Microsoft Assault Extends Past Outlook, Wiz Studies

Azure AD Token Forging Approach in Microsoft Assault Extends Past Outlook, Wiz Studies

July 21, 2023
Anthony Joshua “would have knocked out a major Mike Tyson” in response to Larry Holmes

Anthony Joshua “would have knocked out a major Mike Tyson” in response to Larry Holmes

October 4, 2023
Wing Disrupts the Market by Introducing Inexpensive SaaS Safety

Wing Disrupts the Market by Introducing Inexpensive SaaS Safety

October 4, 2023
Dana White eyeing the Sphere for Mexican Independence Day 2024

Dana White eyeing the Sphere for Mexican Independence Day 2024

October 4, 2023
Leigh Wooden vs Josh Warrington media exercise

Leigh Wooden vs Josh Warrington media exercise

October 4, 2023
Tawanchai to proceed quest for two-sport glory at ONE Combat Night time 15

Tawanchai to proceed quest for two-sport glory at ONE Combat Night time 15

October 4, 2023
Artistic Mom-Daughter Date Concepts for Fall

Artistic Mom-Daughter Date Concepts for Fall

October 4, 2023
This week, a temblor reshaped California politics

This week, a temblor reshaped California politics

October 4, 2023
Linux Vulnerability Exposes Hundreds of thousands of Programs to Assault

Linux Vulnerability Exposes Hundreds of thousands of Programs to Assault

October 4, 2023
Personal Safety News

Get the latest news and follow the coverage of Domestic Violence, Self Defense, Crimes, Bullying, Martial Arts and more from the top trusted sources.

CATEGORIES

  • Bullying
  • Crime
  • Cyber Crimes
  • Domestic Violence
  • Martial Arts
  • MMA
  • Personal Safety
  • Relationship Advice
  • Self Defense
  • Stalking

LATEST UPDATES

  • Anthony Joshua “would have knocked out a major Mike Tyson” in response to Larry Holmes
  • Wing Disrupts the Market by Introducing Inexpensive SaaS Safety
  • Dana White eyeing the Sphere for Mexican Independence Day 2024

Copyright © 2023 Personal Safety News.
Personal Safety News is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Domestic Violence
  • Crime
  • Personal Safety
  • Self Defense
  • Martial Arts
  • Bullying
  • Cyber Crimes
  • Stalking
  • Relationship Advice
  • MMA

Copyright © 2023 Personal Safety News.
Personal Safety News is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In