CVE Vulnerabilities

CVE-2025-30064

Improper Verification of Cryptographic Signature

Published: Aug 27, 2025 | Modified: Aug 27, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not verify which signing algorithm was used. As a result, an attacker can use the ex:action parameter in the VerifyUserByThrustedService function to generate a session for any user.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

References