CVE-2024-51744

EUVD-2024-3178
golang-jwt is a Go implementation of JSON Web Tokens. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are potentially not checking errors in the way they should be. Especially, if a token is both expired and invalid, the errors returned by `ParseWithClaims` return both error codes. If users only check for the `jwt.ErrTokenExpired ` using `error.Is`, they will ignore the embedded `jwt.ErrTokenSignatureInvalid` and thus potentially accept invalid tokens. A fix has been back-ported with the error handling logic from the `v5` branch to the `v4` branch. In this logic, the `ParseWithClaims` function will immediately return in "dangerous" situations (e.g., an invalid signature), limiting the combined errors only to situations where the signature is valid, but further validation failed (e.g., if the signature is valid, but is expired AND has the wrong audience). This fix is part of the 4.5.1 release. We are aware that this changes the behaviour of an established function and is not 100 % backwards compatible, so updating to 4.5.1 might break your code. In case you cannot update to 4.5.0, please make sure that you are properly checking for all errors ("dangerous" ones first), so that you are not running in the case detailed above.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.1 LOW
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
Debian logo
Debian Releases
Debian Product
Codename
golang-github-golang-jwt-jwt
bookworm
no-dsa
forky
5.0.0+really4.5.2-1
fixed
sid
5.0.0+really4.5.2-1
fixed
trixie
5.0.0+really4.5.2-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang-github-golang-jwt-jwt
focal
dne
jammy
needs-triage
noble
needs-triage
oracular
ignored
plucky
needs-triage
questing
needs-triage
golang-github-golang-jwt-jwt-v5
focal
dne
jammy
dne
noble
needs-triage
oracular
ignored
plucky
needs-triage
questing
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
cosign
suse enterprise desktop 15 SP6
2.5.0-150400.3.27.1
fixed
suse enterprise desktop 15 SP7
2.5.0-150400.3.27.1
fixed
suse enterprise sap 15 SP4
2.5.0-150400.3.27.1
fixed
suse enterprise sap 15 SP5
2.5.0-150400.3.27.1
fixed
suse enterprise sap 15 SP6
2.5.0-150400.3.27.1
fixed
suse enterprise sap 15 SP7
2.5.0-150400.3.27.1
fixed
suse enterprise server 15 SP4
2.5.0-150400.3.27.1
fixed
suse enterprise server 15 SP5
2.5.0-150400.3.27.1
fixed
suse enterprise server 15 SP6
2.5.0-150400.3.27.1
fixed
suse enterprise server 15 SP7
2.5.0-150400.3.27.1
fixed
cosign-bash-completion
suse enterprise desktop 15 SP7
2.5.0-150400.3.27.1
fixed
suse enterprise sap 15 SP7
2.5.0-150400.3.27.1
fixed
suse enterprise server 15 SP7
2.5.0-150400.3.27.1
fixed
cosign-zsh-completion
suse enterprise desktop 15 SP7
2.5.0-150400.3.27.1
fixed
suse enterprise sap 15 SP7
2.5.0-150400.3.27.1
fixed
suse enterprise server 15 SP7
2.5.0-150400.3.27.1
fixed
supportutils-plugin-salt
suse enterprise desktop 15 SP6
1.2.3-150000.3.16.1
fixed
suse enterprise desktop 15 SP7
1.2.3-150000.3.16.1
fixed
suse enterprise sap 15 SP3
1.2.3-150000.3.16.1
fixed
suse enterprise sap 15 SP4
1.2.3-150000.3.16.1
fixed
suse enterprise sap 15 SP5
1.2.3-150000.3.16.1
fixed
suse enterprise sap 15 SP6
1.2.3-150000.3.16.1
fixed
suse enterprise sap 15 SP7
1.2.3-150000.3.16.1
fixed
suse enterprise server 15 SP3
1.2.3-150000.3.16.1
fixed
suse enterprise server 15 SP4
1.2.3-150000.3.16.1
fixed
suse enterprise server 15 SP5
1.2.3-150000.3.16.1
fixed
suse enterprise server 15 SP6
1.2.3-150000.3.16.1
fixed
suse enterprise server 15 SP7
1.2.3-150000.3.16.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
docker
Amazon Linux 2023
0:25.0.8-1.amzn2023.0.1
fixed
docker-debuginfo
Amazon Linux 2023
0:25.0.8-1.amzn2023.0.1
fixed
docker-debugsource
Amazon Linux 2023
0:25.0.8-1.amzn2023.0.1
fixed
runfinch-finch
Amazon Linux 2023
0:1.6.0-1.amzn2023.0.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
application-gateway-kubernetes-ingress
Azure Linux 3.0
0:1.7.7-1.azl3
fixed
CBL-Mariner 2.0
0:1.4.0-25.cm2
fixed
azcopy
Azure Linux 3.0
0:10.25.1-4.azl3
fixed
CBL-Mariner 2.0
0:10.25.1-4.cm2
fixed
cert-manager
Azure Linux 3.0
0:1.12.15-1.azl3
fixed
CBL-Mariner 2.0
0:1.11.2-22.cm2
fixed
cf-cli
CBL-Mariner 2.0
0:8.4.0-24.cm2
fixed
coredns
Azure Linux 3.0
0:1.11.4-1.azl3
fixed
CBL-Mariner 2.0
0:1.11.1-18.cm2
fixed
dcos-cli
Azure Linux 3.0
0:1.2.0-18.azl3
fixed
CBL-Mariner 2.0
0:1.2.0-21.cm2
fixed
etcd
Azure Linux 3.0
0:3.5.18-1.azl3
fixed
CBL-Mariner 2.0
0:3.5.21-1.cm2
fixed
flannel
Azure Linux 3.0
0:0.24.2-13.azl3
fixed
influxdb
Azure Linux 3.0
0:2.7.5-3.azl3
fixed
CBL-Mariner 2.0
0:2.6.1-22.cm2
fixed
jx
Azure Linux 3.0
0:3.10.182-1.azl3
fixed
CBL-Mariner 2.0
0:3.2.236-21.cm2
fixed
keda
Azure Linux 3.0
0:2.14.1-6.azl3
fixed
CBL-Mariner 2.0
0:2.4.0-29.cm2
fixed
kube-vip-cloud-provider
CBL-Mariner 2.0
0:0.0.2-22.cm2
fixed
kubernetes
Azure Linux 3.0
0:1.30.10-5.azl3
fixed
CBL-Mariner 2.0
0:0.0.0.cm2
fixed
kubevirt
CBL-Mariner 2.0
0:0.59.0-27.cm2
fixed
moby-engine
Azure Linux 3.0
0:25.0.3-13.azl3
fixed
CBL-Mariner 2.0
0:24.0.9-17.cm2
fixed
packer
Azure Linux 3.0
0:1.9.5-8.azl3
fixed
CBL-Mariner 2.0
0:1.9.5-11.cm2
fixed
prometheus
Azure Linux 3.0
0:2.45.4-12.azl3
fixed
CBL-Mariner 2.0
0:2.37.9-4.cm2
fixed
rook
CBL-Mariner 2.0
0:1.6.2-26.cm2
fixed
telegraf
Azure Linux 3.0
0:1.31.0-6.azl3
fixed
CBL-Mariner 2.0
0:1.29.4-14.cm2
fixed