Skip to content

Authentication Bypass in lua-resty-jwt #9809

Description

@nemmerich

Description

The lua-resty-jwt and api7-lua-resty-jwt dependencies contain an authentication bypass with makes the jwt-auth plugin also vulnerable. As the vulnerability was not fixed for over a year in the lua-resty-jwt library details were made public through cdbattags/lua-resty-jwt#62.

This issue is intended to make the authors of the jwt-auth plugin aware of this vulnerability.

Environment

  • APISIX version (run apisix version):
  • Operating system (run uname -a):
  • OpenResty / Nginx version (run openresty -V or nginx -V):
  • etcd version, if relevant (run curl http://127.0.0.1:9090/v1/server_info):
  • APISIX Dashboard version, if relevant:
  • Plugin runner version, for issues related to plugin runners:
  • LuaRocks version, for installation issues (run luarocks --version):

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

Status
✅ Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions