CWE-347 · 799 записей
Некорректная проверка криптографической подписи
Почему это происходит?
Проверяющая сторона берёт алгоритм проверки из заголовка самого токена. В результате недоверенные данные сами задают правило своей проверки.
Уязвимый и исправленный код
Показательный учебный пример. Выделенные строки показывают, где ошибка и где исправление.
Уязвимый код
const claims = jwt.verify(token, publicKey);Исправленный код
const claims = jwt.verify(token, publicKey, { algorithms: ["RS256"], issuer: "https://id.example.com", audience: "portal",});Как предотвратить
- 01Жёстко задавайте допустимый алгоритм на сервере.
- 02Обязательно проверяйте поля издателя (iss), получателя (aud) и срока действия (exp).
- 03Не смешивайте асимметричные и симметричные схемы проверки на одном эндпоинте.
CVE этого класса
800 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
89Срочно | CVE-2025-59718Готовый эксплойт | A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, Fortifortinet · fortiproxy · CWE-347 | Критическая9,8 | KEV | 68,3 % | 9 дек. 2025 г. |
73На этой неделе | CVE-2020-1464Готовый эксплойт | Windows Spoofing Vulnerabilitymicrosoft · windows 10 1507 · CWE-347 | Высокая7,8 | KEV | 38,9 % | 17 авг. 2020 г. |
71На этой неделе | CVE-2020-2021Готовый эксплойт | PAN-OS: Authentication Bypass in SAML Authenticationpaloaltonetworks · pan-os · CWE-347 | Критическая10,0 | KEV | 4,4 % | 29 июн. 2020 г. |
70На этой неделе | CVE-2026-48558Готовый эксплойт | SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verificationsimple-help · simplehelp · CWE-347 | Критическая9,5 | KEV | 5,7 % | 12 июн. 2026 г. |
70На этой неделе | CVE-2026-5430Готовый эксплойт | Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeoverwso2 · api control plane · CWE-347 | Критическая10,0 | KEV | 0,6 % | 6 авг. 2026 г. |
65На этой неделе | CVE-2013-3900Готовый эксплойт | WinVerifyTrust Signature Validation Vulnerabilitymicrosoft · windows 10 1507 · CWE-347 | Средняя5,5 | KEV | 44,6 % | 10 дек. 2013 г. |
57В плане | CVE-2025-25292Эксплойта нет | Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)omniauth · omniauth saml · CWE-347 | Критическая9,3 | — | 65,1 % | 12 мар. 2025 г. |
55В плане | CVE-2021-22160Эксплойта нет | Authentication with JWT allows use of “none”-algorithmapache · pulsar · CWE-347 | Критическая9,8 | — | 52,9 % | 26 мая 2021 г. |
51В плане | CVE-2018-16042Эксплойта нет | Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earadobe · acrobat dc · CWE-347 | Средняя6,5 | — | 82,4 % | 18 янв. 2019 г. |
49В плане | CVE-2025-47827Готовый эксплойт | In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature.igel · igel os · CWE-347 | Средняя4,6 | KEV | 4,9 % | 5 июн. 2025 г. |
48В плане | CVE-2025-59719Эксплойта нет | An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 tfortinet · fortiweb · CWE-347 | Критическая9,8 | — | 29,2 % | 9 дек. 2025 г. |
46В плане | CVE-2024-9487Proof of concept | An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassedgithub · enterprise server · CWE-347 | Критическая9,5 | — | 25,6 % | 10 окт. 2024 г. |
43В плане | CVE-2018-0114Proof of concept | A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens ucisco · node-jose · CWE-347 | Высокая7,5 | — | 42,7 % | 4 янв. 2018 г. |
43В плане | CVE-2025-25291Proof of concept | ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)omniauth · omniauth saml · CWE-347 | Критическая9,3 | — | 20,6 % | 12 мар. 2025 г. |
42В плане | CVE-2024-45409Proof of concept | The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selectoronelogin · ruby-saml · CWE-347 | Критическая9,8 | — | 10,7 % | 10 сент. 2024 г. |
41В плане | CVE-2021-37160Эксплойта нет | A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of softwarswisslog-healthcare · hmi-3 control panel firmware · CWE-347 | Критическая9,8 | — | 8,2 % | 2 авг. 2021 г. |
41В плане | CVE-2021-33885Эксплойта нет | An Insufficient Verification of Data Authenticity vulnerability in B.bbraun · spacecom2 · CWE-347 | Критическая9,8 | — | 5,6 % | 25 авг. 2021 г. |
40В плане | CVE-2025-29775Proof of concept | xml-crypto Vulnerable to XML Signature Verification Bypass via DigestValue Commentnode-saml · xml-crypto · CWE-347 | Критическая9,3 | — | 9,5 % | 14 мар. 2025 г. |
40В плане | CVE-2025-29774Proof of concept | xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo Referencesnode-saml · xml-crypto · CWE-347 | Критическая9,3 | — | 9,1 % | 14 мар. 2025 г. |
40В плане | CVE-2018-12356Эксплойта нет | An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2.simple password store project · simple password store · CWE-347 | Критическая9,8 | — | 4,6 % | 14 июн. 2018 г. |
40В плане | CVE-2018-8955Эксплойта нет | The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which albitdefender · gravityzone · CWE-347 | Критическая9,8 | — | 4,3 % | 24 окт. 2018 г. |
40В плане | CVE-2018-1000076Эксплойта нет | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 seriesrubygems · rubygems · CWE-347 | Критическая9,8 | — | 2,9 % | 13 мар. 2018 г. |
40В плане | CVE-2019-6318Эксплойта нет | HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP Officejet Enterprise printers have an inshp · color laserjet cm4540 mfp firmware · CWE-347 | Критическая9,8 | — | 2,6 % | 11 апр. 2019 г. |
40В плане | CVE-2018-5923Эксплойта нет | In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet Enterprise Printers, solution application signaturehp · color laserjet cm4540 mfp firmware · CWE-347 | Критическая9,8 | — | 2,6 % | 27 мар. 2019 г. |
40В плане | CVE-2021-37927Эксплойта нет | Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.zohocorp · manageengine admanager plus · CWE-347 | Критическая9,8 | — | 2,2 % | 22 сент. 2021 г. |
- CVE-2025-5971889Срочно
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, Forti
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 68 %fortinet · fortiproxy9 дек. 2025 г.
- CVE-2020-146473На этой неделе
Windows Spoofing Vulnerability
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 39 %microsoft · windows 10 150717 авг. 2020 г.
- CVE-2020-202171На этой неделе
PAN-OS: Authentication Bypass in SAML Authentication
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 4 %paloaltonetworks · pan-os29 июн. 2020 г.
- CVE-2026-4855870На этой неделе
SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
КритическаяCVSS 9,5KEVГотовый эксплойтEPSS 6 %simple-help · simplehelp12 июн. 2026 г.
- CVE-2026-543070На этой неделе
Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 1 %wso2 · api control plane6 авг. 2026 г.
- CVE-2013-390065На этой неделе
WinVerifyTrust Signature Validation Vulnerability
СредняяCVSS 5,5KEVГотовый эксплойтEPSS 45 %microsoft · windows 10 150710 дек. 2013 г.
- CVE-2025-2529257В плане
Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)
КритическаяCVSS 9,3Эксплойта нетEPSS 65 %omniauth · omniauth saml12 мар. 2025 г.
- CVE-2021-2216055В плане
Authentication with JWT allows use of “none”-algorithm
КритическаяCVSS 9,8Эксплойта нетEPSS 53 %apache · pulsar26 мая 2021 г.
- CVE-2018-1604251В плане
Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and ear
СредняяCVSS 6,5Эксплойта нетEPSS 82 %adobe · acrobat dc18 янв. 2019 г.
- CVE-2025-4782749В плане
In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature.
СредняяCVSS 4,6KEVГотовый эксплойтEPSS 5 %igel · igel os5 июн. 2025 г.
- CVE-2025-5971948В плане
An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 t
КритическаяCVSS 9,8Эксплойта нетEPSS 29 %fortinet · fortiweb9 дек. 2025 г.
- CVE-2024-948746В плане
An Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed
КритическаяCVSS 9,5Proof of conceptEPSS 26 %github · enterprise server10 окт. 2024 г.
- CVE-2018-011443В плане
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens u
ВысокаяCVSS 7,5Proof of conceptEPSS 43 %cisco · node-jose4 янв. 2018 г.
- CVE-2025-2529143В плане
ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)
КритическаяCVSS 9,3Proof of conceptEPSS 21 %omniauth · omniauth saml12 мар. 2025 г.
- CVE-2024-4540942В плане
The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector
КритическаяCVSS 9,8Proof of conceptEPSS 11 %onelogin · ruby-saml10 сент. 2024 г.
- CVE-2021-3716041В плане
A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of softwar
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %swisslog-healthcare · hmi-3 control panel firmware2 авг. 2021 г.
- CVE-2021-3388541В плане
An Insufficient Verification of Data Authenticity vulnerability in B.
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %bbraun · spacecom225 авг. 2021 г.
- CVE-2025-2977540В плане
xml-crypto Vulnerable to XML Signature Verification Bypass via DigestValue Comment
КритическаяCVSS 9,3Proof of conceptEPSS 10 %node-saml · xml-crypto14 мар. 2025 г.
- CVE-2025-2977440В плане
xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References
КритическаяCVSS 9,3Proof of conceptEPSS 9 %node-saml · xml-crypto14 мар. 2025 г.
- CVE-2018-1235640В плане
An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %simple password store project · simple password store14 июн. 2018 г.
- CVE-2018-895540В плане
The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which al
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %bitdefender · gravityzone24 окт. 2018 г.
- CVE-2018-100007640В плане
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %rubygems · rubygems13 мар. 2018 г.
- CVE-2019-631840В плане
HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP Officejet Enterprise printers have an ins
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %hp · color laserjet cm4540 mfp firmware11 апр. 2019 г.
- CVE-2018-592340В плане
In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet Enterprise Printers, solution application signature
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %hp · color laserjet cm4540 mfp firmware27 мар. 2019 г.
- CVE-2021-3792740В плане
Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %zohocorp · manageengine admanager plus22 сент. 2021 г.