SCA: security update for jsonwebtoken (GHSA-hjrf-2m68-5959)

medium Tenable Cloud Security Plugin ID 415817

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- jsonwebtoken is an implementation of JSON Web Tokens. Versions `<= 8.5.1` of `jsonwebtoken` library can be
misconfigured so that passing a poorly implemented key retrieval function referring to the
`secretOrPublicKey` argument from the readme link will result in incorrect verification of tokens. There
is a possibility of using a different algorithm and key combination in verification, other than the one
that was used to sign the tokens. Specifically, tokens signed with an asymmetric public key could be
verified with a symmetric HS256 algorithm. This can lead to successful validation of forged tokens. If
your application is supporting usage of both symmetric key and asymmetric key in jwt.verify()
implementation with the same key retrieval function. This issue has been patched, please update to version
9.0.0. (CVE-2022-23541)

See Also

https://github.com/advisories/GHSA-hjrf-2m68-5959

Plugin Details

Severity: Medium

ID: 415817

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.8

Percentile: 22.22

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2022-23541

CVSS v3

Risk Factor: Medium

Base Score: 6.3

Temporal Score: 5.5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/22/2022

Vulnerability Publication Date: 12/22/2022

Reference Information

CVE: CVE-2022-23541