ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, , true, algorithm: HS256) accepts an attacker-forged token because OpenSSL::HMAC.digest(SHA256, , payload) returns a valid digest under an empty key and no empty-key precondition exists in the HMAC algorithm. The same path is reached when a keyfinder block or key_finder: argument returns an empty string, nil, or an array containing nil for an unknown key, affecting HS256, HS384, and HS512 verification through JWT.decode and JWT::EncodedToken#verify_signature!. This issue is fixed in versions 2.10.3 and 3.2.0.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | rubygem-jwt-0:2.10.3-1.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | rubygem-jwt-0:2.10.3-1.el9sat | * |
| Red Hat Satellite 6.17 for RHEL 9 | RedHat | ansible-core-1:2.16.19-1.el9sat | * |
| Red Hat Satellite 6.17 for RHEL 9 | RedHat | rubygem-jwt-0:2.10.3-1.el9sat | * |
| Red Hat Satellite 6.17 for RHEL 9 | RedHat | ansible-core-1:2.16.19-1.el9sat | * |
| Red Hat Satellite 6.17 for RHEL 9 | RedHat | rubygem-jwt-0:2.10.3-1.el9sat | * |
| Red Hat Satellite 6.18 for RHEL 9 | RedHat | pulpcore-obsolete-packages-0:1.3.1-5.el9pc | * |
| Red Hat Satellite 6.18 for RHEL 9 | RedHat | python3.12-pulpcore-0:3.73.30-3.el9pc | * |
| Red Hat Satellite 6.18 for RHEL 9 | RedHat | rubygem-jwt-0:2.10.3-1.el9sat | * |
| Red Hat Satellite 6.19 for RHEL 9 | RedHat | rubygem-jwt-0:2.10.3-1.el9sat | * |