CVE-2024-37568 describes an algorithm confusion vulnerability in Authlib versions prior to 1.3.1, where HMAC verification can be performed with any asymmetric public key if no algorithm is explicitly specified during a jwt.decode call. This flaw, similar to previous CVEs, impacts the security of applications using Authlib for JWT processing. The vulnerability carries a CVSS score of 7.5 (HIGH), indicating a network-exploitable issue with low attack complexity and high integrity impact, allowing an attacker to potentially forge JWTs. There is no confidentiality or availability impact. Currently, there is no known active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. While there's limited community discussion, the vulnerability has received media coverage, notably from Ubuntu Security, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.1CPE matchmatch criteria | cpe:2.3:a:authlib:authlib:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.