Source: golang-github-golang-jwt-jwt
Version: 5.0.0+really4.5.0-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for golang-github-golang-jwt-jwt.
CVE-2024-51744[0]:
| golang-jwt is a Go implementation of JSON Web Tokens. Unclear
| documentation of the error behavior in `ParseWithClaims` can lead to
| situation where users are potentially not checking errors in the way
| they should be. Especially, if a token is both expired and invalid,
| the errors returned by `ParseWithClaims` return both error codes. If
| users only check for the `jwt.ErrTokenExpired ` using `error.Is`,
| they will ignore the embedded `jwt.ErrTokenSignatureInvalid` and
| thus potentially accept invalid tokens. A fix has been back-ported
| with the error handling logic from the `v5` branch to the `v4`
| branch. In this logic, the `ParseWithClaims` function will
| immediately return in "dangerous" situations (e.g., an invalid
| signature), limiting the combined errors only to situations where
| the signature is valid, but further validation failed (e.g., if the
| signature is valid, but is expired AND has the wrong audience). This
| fix is part of the 4.5.1 release. We are aware that this changes the
| behaviour of an established function and is not 100 % backwards
| compatible, so updating to 4.5.1 might break your code. In case you
| cannot update to 4.5.0, please make sure that you are properly
| checking for all errors ("dangerous" ones first), so that you are
| not running in the case detailed above.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2024-51744
https://www.cve.org/CVERecord?id=CVE-2024-51744
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2323735
[2]
https://github.com/golang-jwt/jwt/commit/7b1c1c00a171c6c79bbdb40e4ce7d197060c1c2c
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore