Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in the PyJWT library could allow attackers to potentially disclose credentials or substitute verification keys by exploiting improperly revalidated redirect destinations in the JWKS trust boundary. This affects applications using this library for handling JSON Web Tokens, and the primary concern is to confirm if our systems utilize the affected versions and configurations.
- Tokens may be compromised by redirect issues.
- Trust boundary flaws enable credential disclosure.
- Confirm use of affected PyJWT versions.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this by tricking a system that uses PyJWT into fetching JSON Web Key Set (JWKS) data from a malicious source. If the system is configured to trust a JWKS endpoint that an attacker influences to redirect to their own controlled endpoint, the system will then process the attacker's response as valid key material. This could lead to the disclosure of sensitive credentials or the substitution of verification keys, allowing the attacker to potentially impersonate users or forge tokens.
- Unauthenticated network access required.
- Malicious JWKS endpoint redirect.
- Sensitive data disclosure or key substitution.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an attacker to disclose forwarded credentials or substitute verification keys when a configured trusted JWKS endpoint returns an attacker-influenced redirect. This occurs because the PyJWKClient does not revalidate redirect destinations against the JWKS trust boundary.
- Forwarded credentials could be disclosed.
- Attacker-influenced redirects may occur.
- Verification keys could be maliciously substituted.
Operational Fix
Recommended remediation, mitigation, and detection steps
In a real-world scenario, application owners and platform teams are most likely responsible for addressing this vulnerability, as it affects a software library used within applications. The initial step is to identify all instances of the affected PyJWT library, confirm their reachability and business criticality, and then engage the accountable owner to plan remediation.
- Application owners must own the issue.
- Verify JWKS endpoint configurations first.
- Plan remediation based on risk.