All incidents

Security issue in experimental JWT authentication in v3.3

PBL-06-008 WP3: JWT key confusion leads to authentication bypass (High) (BETA)

Summary

  • CVE: N/A.
  • Product affected: API (Pro and CE).
  • Version affected: v3.3.0
  • Version fixed: v3.3.1
  • Affected component: JWT Authentication plugin.
  • Vulnerability Type: Authentication bypass.
  • Severity: High (8.3).

Attack vector / exploitation

Fix

Severity

Follow up

Event timeline

  • 2021-11-24 10:30 CET: Vulnerability details sent by reporter.
  • 2021-11-24 10:30 CET: We acknowledge the issue, start working on a fix
  • 2021-11-24 12:50 CET: A fix is proposed to the reporter
  • 2021-11-24 16:40 PM CET: We publish the fix as part of v3.3.1 release
  • 2021-11-24 17:00 PM CET: We publish the release notes and this report.

Current status:

Last updated: 2021-11-24 16:30:00 CET
Flag of European UnionMade in Europe. Privacy by default.
Passbolt Security Incident Report: audit - November 24th, 2021