Sploitus

CVE-2020-28042

4 known exploits for CVE-2020-28042

ServiceStack before 5.9.2 mishandles JWT signature verification unless an application has a custom ValidateToken function that establishes a valid minimum length for a signature.

Affected products
Servicestack
Servicestack
< 5.9.2
Fix
Available
CVSS 3.1
5.3 MEDIUM
EPSS
2.3% (82th percentile)
Weakness
CWE-347
NVD status
Modified
Published
2020-11-01
CVE-2020-28042 at NVD
Authoritative description, scoring and affected products

4 known exploits for CVE-2020-28042

Proof-of-concept code and exploit modules indexed by Sploitus