Algorithm Confusion in Lepture Authlib (CVE-2024-37568)

Algorithm Confusion in Lepture Authlib (CVE-2024-37568)

CVEs

7.5 High Severity

Screenshots from the blog posts

images/clysmkhlqgrwh1gn9a6jygzz5.pngimages/clysmkhlqgrwh1gn9a6jygzz5.png

Summary

Algorithm confusion affects versions before version 1.3.1 of Lepture Authib due to the permission of HMAC verification when handling asymmetric public keys. This analysis investigates this vulnerability and how it can be mitigated to keep attackers away.

Description

Total vcoins

9.8K

Social media links

Comments (0)