2019å¹´1æ30æ¥ PST æ¬èå¼±æ§ã®æªç¨ã·ããªãªã®åææ¡ä»¶ã«é¢ããã³ãã¥ããã£ããã®ãã£ã¼ãããã¯ãåããç§ãã¡ã¯Auth0ã¨ååãã¦CVE-2022-23529ãæ¤åãããã¨ã決å®ãã¾ããã æ¬ç¨¿ã§è§£èª¬ããã»ãã¥ãªãã£ã®åé¡ã¯JsonWebTokenã©ã¤ãã©ãªãå®å ¨ã§ãªãæ¹æ³ã§ä½¿ç¨ãããå ´åã«ã¯ä¾ç¶ã¨ãã¦æ¸å¿µããããã®ã§ãããã®ã·ããªãªã§ã¯ããã¹ã¦ã®åææ¡ä»¶ãæºããã°ãã®åé¡ãæªç¨ã§ããå¯è½æ§ãããã¾ããç§ãã¡ã¯ããã®å ´åã®ãªã¹ã¯ã®å¤§å ã¯ã©ã¤ãã©ãªå´ã§ãªãå¼ã³åºãå´ã®ã³ã¼ãã«ãããã¨ã«åæãã¾ãã ãã®åé¡ã«å¯¾å¦ããããJsonWebTokenã®ã³ã¼ãã«ã¯éè¦ãªã»ãã¥ãªãã£ãã§ãã¯ã追å ããã¾ããã jsonwebtoken 8.5.1以åã®ãã¼ã¸ã§ã³ãã使ãã®å ´åã¯ææ°çã®9.0.0ã«ã¢ãããã¼ããããã¨ããå§ããã¾ããææ°çã§ã¯åã»ãã¥ãªãã£åé¡ãå«ãåé¡ãä¿®æ£æ¸ã¿ã§ãããå®å ¨ãª
![[2023-01-31 12:00 JST æ´æ°] JWTã®ã·ã¼ã¯ã¬ãããã¤ãºãã³ã°ã«é¢ããåé¡](https://cdn-ak-scissors.b.st-hatena.com/image/square/f74e9575220c49b6d66889f97b3d377182740fe5/height=288;version=1;width=512/https%3A%2F%2Funit42.paloaltonetworks.jp%2Fwp-content%2Fuploads%2F2024%2F06%2F02_Cloud_cybersecurity_research_Overview_1920x900.jpg)
{{#tags}}- {{label}}
{{/tags}}