mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-30 21:39:29 +02:00
1009 B
1009 B
CVE-2020-28042
Description
ServiceStack before 5.9.2 mishandles JWT signature verification unless an application has a custom ValidateToken function that establishes a valid minimum length for a signature.
POC
Reference
Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/The-Cracker-Technology/jwt_tool
- https://github.com/crpytoscooby/resourses_web
- https://github.com/mishmashclone/ticarpi-jwt_tool
- https://github.com/phramz/tc2022-jwt101
- https://github.com/puckiestyle/jwt_tool
- https://github.com/ticarpi/jwt_tool
- https://github.com/zhangziyang301/jwt_tool