CVE-2018-0114 describes a critical vulnerability in the Cisco node-jose open source library (versions prior to 0.11.0) that allows unauthenticated, remote attackers to re-sign JSON Web Tokens (JWTs). This flaw stems from the library's adherence to the JSON Web Signature (JWS) standard, which permits embedding a public key within the JWS header for verification. An attacker can exploit this by replacing the original signature, inserting an attacker-controlled public key into the header, and then signing the token with their corresponding private key, effectively forging valid JWS objects. The vulnerability carries a high CVSS score of 7.5, indicating a severe impact with a network attack vector and low attack complexity, potentially leading to high integrity compromise without requiring user interaction. While not currently listed in CISA's KEV catalog, an exploit (EDB-44324) is publicly available on ExploitDB, confirming its exploitability. Despite the public exploit, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.11.0CPE matchmatch criteria | cpe:2.3:a:cisco:node-jose:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.