VDB

RHSA-2021%3A5110

RHSA-2021%3A5110 PUBLISHED CVSS 7.5 HIGH

A vulnerability was found in jwt-go where it is vulnerable to Access Restriction Bypass if m["aud"] happens to be []string{}, as allowed by the spec, the type assertion fails and the value of aud is "". This can cause audience verification to succeed even if the audiences being passed are incorrect if required is set to false.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Red Hatcryostat-20-tech-preview/cryostat-operator-bundle@sha256:afb5bdabd4353342627a4dac51df35472c944884eb7cfe051133527eb819860d_amd64 as a component of Cryostat 2 on RHEL 8cryostat-20-tech-preview/cryostat-operator-bundle@sha256:afb5bdabd4353342627a4dac51df35472c944884eb7cfe051133527eb819860d_amd64
Red Hatcryostat-20-tech-preview/cryostat-operator-bundle@sha256:afb5bdabd4353342627a4dac51df35472c944884eb7cfe051133527eb819860d_amd64 as a component of Cryostat 2 on RHEL 8cryostat-20-tech-preview/cryostat-operator-bundle@sha256:afb5bdabd4353342627a4dac51df35472c944884eb7cfe051133527eb819860d_amd64, *
Red Hatcryostat-20-tech-preview/cryostat-rhel8-operator@sha256:0646433e7541caceeba935439b7d0d388604350da1fb16b7a3fa0f8f3465e191_amd64 as a component of Cryostat 2 on RHEL 8*
Red Hatcryostat-20-tech-preview/cryostat-rhel8-operator@sha256:0646433e7541caceeba935439b7d0d388604350da1fb16b7a3fa0f8f3465e191_amd64 as a component of Cryostat 2 on RHEL 8*, *

Timeline

  • Dec 14, 2021 CVE Published
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • May 15, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›