Signature Verification Bypass
Discription
Oracle Java SE and Oracle GraalVM Enterprise Edition product of Oracle Java SE (their component: Libraries) are vulnerable to signature verification bypass. The vulnerability is possible due to a flawed implementation of ECDSA verification code rewritten from native C++ code, allowing an attacker to forge signature and bypass signature verification. The vulnerability exists only for Java 15, 16, 17, or 18 version.Read More
References
https://bitbucket.org/connect2id/nimbus-jose-jwt/commits/651580526d8e815420e06abe31c0b4976c4afec9https://bugs.openjdk.java.net/browse/JDK-8235710https://docs.oracle.com/en/graalvm/enterprise/20/docs/overview/release-noteshttps://connect2id.com/blog/cve-2022-21449https://bugs.openjdk.java.net/browse/JDK-8285389https://www.debian.org/security/2022/dsa-5128https://www.debian.org/security/2022/dsa-5131https://backstage.forgerock.com/knowledge/kb/article/a90257583https://security.netapp.com/advisory/ntap-20220429-0006/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://neilmadden.blog/2022/04/19/psychic-signatures-in-javahttps://openjdk.java.net/groups/vulnerability/advisories/2022-04-19http://www.openwall.com/lists/oss-security/2022/04/28/2http://www.openwall.com/lists/oss-security/2022/04/28/3http://www.openwall.com/lists/oss-security/2022/04/28/4http://www.openwall.com/lists/oss-security/2022/04/28/5http://www.openwall.com/lists/oss-security/2022/04/28/6http://www.openwall.com/lists/oss-security/2022/04/28/7http://www.openwall.com/lists/oss-security/2022/04/29/1http://www.openwall.com/lists/oss-security/2022/04/30/4http://www.openwall.com/lists/oss-security/2022/04/30/1http://www.openwall.com/lists/oss-security/2022/04/30/2http://www.openwall.com/lists/oss-security/2022/04/30/3http://www.openwall.com/lists/oss-security/2022/05/01/1http://www.openwall.com/lists/oss-security/2022/05/01/2http://www.openwall.com/lists/oss-security/2022/05/02/1https://github.com/khalednassar/CVE-2022-21449-TLS-PoChttps://neilmadden.blog/2022/04/25/a-few-clarifications-about-cve-2022-21449CVSS2
- Access Vector
- Access Complexity
- Authentication
- Confidentiality Impact
- Integrity Impact
- Availability Impact
- Network
- Low
- None
- None
- Partial
- None
AV:N/AC:L/Au:N/C:N/I:P/A:N
CVSS3
- Attack Vector
- Attack Complexity
- Privileges Required
- User Interaction
- Scope
- Confidentiality Impact
- Integrity Impact
- Availability Impact
- Network
- Low
- None
- None
- Unchanged
- None
- High
- None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Back to Main