CVE-2024-10125 describes a critical vulnerability in the Amazon.ApplicationLoadBalancer.Identity.AspNetCore middleware, which fails to validate the issuer and signer identity of JSON Web Tokens (JWTs). This flaw, if combined with publicly accessible ALB targets, allows untrusted entities to forge JWTs and mimic valid OIDC-federated sessions. With a CVSS score of 7.5 (High), exploitation is network-based and of high impact to confidentiality and low impact to integrity, but requires high attack complexity. The affected repository is deprecated and unsupported, and there is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Amazon | Amazon.ApplicationLoadBalancer.Identity.AspNetCore Middleware | allCNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.