VDB
RHSA-2021%3A5110
RHSA-2021%3A5110
PUBLISHED
CVSS 7.5 HIGH
A vulnerability was found in jwt-go where it is vulnerable to Access Restriction Bypass if m["aud"] happens to be []string{}, as allowed by the spec, the type assertion fails and the value of aud is "". This can cause audience verification to succeed even if the audiences being passed are incorrect if required is set to false.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | cryostat-20-tech-preview/cryostat-operator-bundle@sha256:afb5bdabd4353342627a4dac51df35472c944884eb7cfe051133527eb819860d_amd64 as a component of Cryostat 2 on RHEL 8 | cryostat-20-tech-preview/cryostat-operator-bundle@sha256:afb5bdabd4353342627a4dac51df35472c944884eb7cfe051133527eb819860d_amd64 |
| Red Hat | cryostat-20-tech-preview/cryostat-operator-bundle@sha256:afb5bdabd4353342627a4dac51df35472c944884eb7cfe051133527eb819860d_amd64 as a component of Cryostat 2 on RHEL 8 | cryostat-20-tech-preview/cryostat-operator-bundle@sha256:afb5bdabd4353342627a4dac51df35472c944884eb7cfe051133527eb819860d_amd64, * |
| Red Hat | cryostat-20-tech-preview/cryostat-rhel8-operator@sha256:0646433e7541caceeba935439b7d0d388604350da1fb16b7a3fa0f8f3465e191_amd64 as a component of Cryostat 2 on RHEL 8 | * |
| Red Hat | cryostat-20-tech-preview/cryostat-rhel8-operator@sha256:0646433e7541caceeba935439b7d0d388604350da1fb16b7a3fa0f8f3465e191_amd64 as a component of Cryostat 2 on RHEL 8 | *, * |
Timeline
- Dec 14, 2021 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- May 15, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2021:5110 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/containers advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1883371 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_5110.json advisory
- https://access.redhat.com/security/cve/CVE-2020-26160 advisory
- https://www.cve.org/CVERecord?id=CVE-2020-26160 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-26160 advisory
- https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMDGRIJALVAJWTGO-596515 advisory