-
Notifications
You must be signed in to change notification settings - Fork 256
Open
Description
Hello world,
The function construct in
Line 63 in 4b0701b
| def construct(key_data, algorithm=None): |
contains an Generation of Error Message Containing Sensitive Information vulnerability that allows an attacker to view the victims Secret Key that is used to sign tokens. With the secret key an attacker would be able to create and sign valid tokens on the victims site and bypass authentication if JWT's are used for authorizing a user via the HTTP Authorization header for example. I've submitted a fix and PR:
Best regards,
mr-n30
neumann-nico
Metadata
Metadata
Assignees
Labels
No labels