CVE Vulnerabilities

CVE-2020-26160

Improper Authentication

Published: Sep 30, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

jwt-go before 4.0.0-preview1 allows attackers to bypass intended access restrictions in situations with []string{} for m[aud] (which is allowed by the specification). Because the type assertion fails, is the value of aud. This is a security problem if the JWT token is presented to a service that lacks its own audience check.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Jwt-goJwt-go_project*3.2.0 (including)
Cryostat 2 on RHEL 8RedHatcryostat-20-tech-preview/cryostat-operator-bundle:2.0.0-6.1639085863*
Cryostat 2 on RHEL 8RedHatcryostat-20-tech-preview/cryostat-rhel8-operator:2.0.0-5*
Openshift Serveless 1.13RedHatopenshift-serverless-1/client-kn-rhel8:0.19.1-4*
Openshift Serveless 1.13RedHatopenshift-serverless-1/eventing-apiserver-receive-adapter-rhel8:0.19.2-3*
Openshift Serveless 1.13RedHatopenshift-serverless-1/eventing-controller-rhel8:0.19.2-3*
Openshift Serveless 1.13RedHatopenshift-serverless-1/eventing-in-memory-channel-controller-rhel8:0.19.2-3*
Openshift Serveless 1.13RedHatopenshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8:0.19.2-3*
Openshift Serveless 1.13RedHatopenshift-serverless-1/eventing-mtbroker-filter-rhel8:0.19.2-3*
Openshift Serveless 1.13RedHatopenshift-serverless-1/eventing-mtbroker-ingress-rhel8:0.19.2-3*
Openshift Serveless 1.13RedHatopenshift-serverless-1/eventing-mtchannel-broker-rhel8:0.19.2-3*
Openshift Serveless 1.13RedHatopenshift-serverless-1/eventing-mtping-rhel8:0.19.2-3*
Openshift Serveless 1.13RedHatopenshift-serverless-1/eventing-storage-version-migration-rhel8:0.19.2-3*
Openshift Serveless 1.13RedHatopenshift-serverless-1/eventing-sugar-controller-rhel8:0.19.2-3*
Openshift Serveless 1.13RedHatopenshift-serverless-1/eventing-webhook-rhel8:0.19.2-3*
Openshift Serveless 1.13RedHatopenshift-serverless-1/ingress-rhel8-operator:1.13.0-6*
Openshift Serveless 1.13RedHatopenshift-serverless-1/knative-rhel8-operator:1.13.0-6*
Openshift Serveless 1.13RedHatopenshift-serverless-1/kn-cli-artifacts-rhel8:0.19.1-2*
Openshift Serveless 1.13RedHatopenshift-serverless-1/kourier-control-rhel8:0.19.0-3*
Openshift Serveless 1.13RedHatopenshift-serverless-1/serverless-operator-bundle:1.13.0-9*
Openshift Serveless 1.13RedHatopenshift-serverless-1/serverless-rhel8-operator:1.13.0-6*
Openshift Serveless 1.13RedHatopenshift-serverless-1/serving-activator-rhel8:0.19.0-5*
Openshift Serveless 1.13RedHatopenshift-serverless-1/serving-autoscaler-hpa-rhel8:0.19.0-5*
Openshift Serveless 1.13RedHatopenshift-serverless-1/serving-autoscaler-rhel8:0.19.0-5*
Openshift Serveless 1.13RedHatopenshift-serverless-1/serving-controller-rhel8:0.19.0-5*
Openshift Serveless 1.13RedHatopenshift-serverless-1/serving-domain-mapping-rhel8:0.19.0-5*
Openshift Serveless 1.13RedHatopenshift-serverless-1/serving-domain-mapping-webhook-rhel8:0.19.0-5*
Openshift Serveless 1.13RedHatopenshift-serverless-1/serving-queue-rhel8:0.19.0-6*
Openshift Serveless 1.13RedHatopenshift-serverless-1/serving-storage-version-migration-rhel8:0.19.0-5*
Openshift Serveless 1.13RedHatopenshift-serverless-1/serving-webhook-rhel8:0.19.0-5*
Openshift Serveless 1.13RedHatopenshift-serverless-1/svls-must-gather-rhel8:1.13.0-3*
Red Hat OpenShift Container Platform 4.7RedHatopenshift4/ose-azure-machine-controllers:v4.7.0-202102130115.p0*
Red Hat OpenShift Container Platform 4.8RedHatopenshift4/ose-baremetal-installer-rhel8:v4.8.0-202106291913.p0.git.a5ddd2d.assembly.stream*
Red Hat OpenShift Container Platform 4.8RedHatopenshift4/ose-etcd:v4.8.0-202106152230.p0.git.aefa6bf.assembly.stream*
Red Hat OpenShift Container Storage 4.7.0 on RHEL-8RedHatocs4/mcg-rhel8-operator:5.7.0-69.85e2026.5.7*
Red Hat OpenShift Container Storage 4.7.0 on RHEL-8RedHatmcg-0:5.7.0-69.85e2026.5.7.el8*
Golang-github-coreos-discovery-etcd-ioUbuntufocal*
Golang-github-coreos-discovery-etcd-ioUbuntugroovy*
Golang-github-coreos-discovery-etcd-ioUbuntuhirsute*
Golang-github-coreos-discovery-etcd-ioUbuntuimpish*
Golang-github-coreos-discovery-etcd-ioUbuntukinetic*
Golang-github-coreos-discovery-etcd-ioUbuntulunar*
Golang-github-coreos-discovery-etcd-ioUbuntumantic*
Golang-github-coreos-discovery-etcd-ioUbuntuoracular*
Golang-github-coreos-discovery-etcd-ioUbuntuplucky*
Golang-github-coreos-discovery-etcd-ioUbuntutrusty*
Golang-github-dgrijalva-jwt-goUbuntubionic*
Golang-github-dgrijalva-jwt-goUbuntufocal*
Golang-github-dgrijalva-jwt-goUbuntugroovy*
Golang-github-dgrijalva-jwt-goUbuntutrusty*
Golang-github-dgrijalva-jwt-goUbuntuxenial*
Juju-coreUbuntutrusty*
TelegrafUbuntugroovy*
TelegrafUbuntuhirsute*
TelegrafUbuntuimpish*
TelegrafUbuntukinetic*
TelegrafUbuntulunar*
TelegrafUbuntumantic*
TelegrafUbuntutrusty*

Potential Mitigations

References