CAPEC-118
CWE-200
ISO27001-A.18.1.4
WASC-13

Json Web Key Set Disclosure

Severity:
Information
Summary

Invicti identified a Json Web Key Set Disclosure.

Impact

Disclosed JSON Web Key Set (JWKS) vulnerability introduces severe risks to the affected system. Potential unauthorized access and impersonation of users due to private key exposure can compromise data integrity, damage the systems reputation, and lead to regulatory non-compliance. Even with only public key exposure, algorithm and key confusion attacks pose additional threats to authentication and authorization mechanisms.

Remediation

This is reported for informational purposes only.

When making your JWK Set public, ensure that private key components are excluded. If the JWK Set only contains public key components, its exposure does not pose a security threat on its own. In fact, utilizing a JWK Set appropriately can be considered a best practice for non-security-related reasons.

Required Skills for Successful Exploitation
Actions To Take
Classifications
Vulnerability Index

You can search and find all vulnerabilities

Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Featured resources

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding

Blog

What lies ahead for CMS.

Blog

How to integrate CMS with other tools.

Blog

Improve user experience through CMS.

Blog

How CMS can benefit e-commerce.

Blog

Stay updated on CMS trends.

Blog

Tips for improving CMS performance.

Blog

Learn how to secure your CMS.

Blog

Explore the advantages of CMS.

Blog

A comprehensive guide to CMS.

Build your resistance to threats. And save hundreds of hours each month.