CVE-2021-46743
JWT Auth – WordPress JSON Web Token Authentication に報告された脆弱性
緊急深刻度
9.1CVSS
2.1.1修正されたバージョン
0.8%30日以内に悪用される確率
概要
In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) header, when multiple types of keys are loaded in a key ring. This allows an attacker to forge tokens that validate under the incorrect key. This may or may not be exploitable in WordPress plugins and themes using the library.
影響を受けるバージョン
- 2.1.0 以下
対処方法
JWT Auth – WordPress JSON Web Token Authentication を 2.1.1 以降に更新してください。これで本脆弱性は解消します。
JWT Auth – WordPress JSON Web Token Authentication の他の脆弱性を見る →
あなたのサイトは大丈夫ですか?
URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。
30秒で無料診断する