Description
The lua-resty-jwt and api7-lua-resty-jwt dependencies contain an authentication bypass with makes the jwt-auth plugin also vulnerable. As the vulnerability was not fixed for over a year in the lua-resty-jwt library details were made public through cdbattags/lua-resty-jwt#62.
This issue is intended to make the authors of the jwt-auth plugin aware of this vulnerability.
Environment
- APISIX version (run
apisix version):
- Operating system (run
uname -a):
- OpenResty / Nginx version (run
openresty -V or nginx -V):
- etcd version, if relevant (run
curl http://127.0.0.1:9090/v1/server_info):
- APISIX Dashboard version, if relevant:
- Plugin runner version, for issues related to plugin runners:
- LuaRocks version, for installation issues (run
luarocks --version):
Description
The lua-resty-jwt and api7-lua-resty-jwt dependencies contain an authentication bypass with makes the
jwt-authplugin also vulnerable. As the vulnerability was not fixed for over a year in the lua-resty-jwt library details were made public through cdbattags/lua-resty-jwt#62.This issue is intended to make the authors of the
jwt-authplugin aware of this vulnerability.Environment
apisix version):uname -a):openresty -Vornginx -V):curl http://127.0.0.1:9090/v1/server_info):luarocks --version):