Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in the PyJWT library could allow an attacker to forge authenticated tokens by treating a public key as a secret key, impacting applications that mix HMAC and asymmetric algorithms. This is particularly concerning as the library is widely used in internet-facing authentication services.
- Forged tokens can bypass authentication.
- Widely used library means broad potential impact.
- Confirm relevance for secure token handling.
Attack Path
How an attacker could exploit the issue
An attacker can forge authenticated HMAC tokens by knowing a public key and then supplying a mutated public-key PEM as raw key bytes. This occurs when an application mixes HMAC and asymmetric algorithms, causing the `is_pem_format` function to misinterpret the asymmetric public key as an HMAC secret. The vulnerability can lead to a critical risk of data integrity compromise and unauthorized access due to token forgery.
- No authentication required to initiate attack.
- Misinterpretation of public key format.
- Forged tokens leading to unauthorized access.
Live Threat
Current exploitation, exposure, and threat context
When an application incorrectly handles public key material, an attacker could forge authenticated tokens. This may occur when using a mix of HMAC and asymmetric algorithms if a mutated public-key PEM is supplied as raw key bytes.
- Authenticated tokens could be forged.
- Malicious tokens may be accepted.
- Unauthorized access is a risk.
Operational Fix
Recommended remediation, mitigation, and detection steps
Application owners and platform teams managing services that use PyJWT for JSON Web Token (JWT) processing are likely responsible for addressing this vulnerability. The first practical step is to inventory all instances of PyJWT, determine which are exposed to the network and handle both HMAC and asymmetric algorithms, and then assess their business criticality to prioritize remediation efforts.
- Identify application owners and affected instances.
- Verify JWT usage with mixed algorithm types.
- Plan remediation during maintenance windows.