CVE-2020-5300 affects Ory Hydra, an OAuth2 server, allowing for replay attacks when using the 'private_key_jwt' client authentication method. The vulnerability stems from Hydra's failure to enforce the uniqueness of the 'jti' assertion in JWTs, which is intended to prevent token reuse. While the CVSS score is Medium (5.3), exploitation is difficult due to TLS protection and the short expiry window of JWTs, limiting the impact to potential information disclosure. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.0CPE matchmatch criteria | cpe:2.3:a:ory:hydra:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.