{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-04T19:21:37.605","vulnerabilities":[{"cve":{"id":"CVE-2020-15084","sourceIdentifier":"security-advisories@github.com","published":"2020-06-30T16:15:15.220","lastModified":"2026-06-17T02:56:01.577","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When algorithms is not specified in the configuration, with the combination of jwks-rsa, it may lead to authorization bypass. You are affected by this vulnerability if all of the following conditions apply: - You are using express-jwt - You do not have **algorithms** configured in your express-jwt configuration. - You are using libraries such as jwks-rsa as the **secret**. You can fix this by specifying **algorithms** in the express-jwt configuration. See linked GHSA for example. This is also fixed in version 6.0.0."},{"lang":"es","value":"En express-jwt (paquete NPM), incluyendo la versión 5.3.3, la entrada de algoritmos que es especificada en la configuración no es aplicada. Cuando los algoritmos no son especificados en la configuración, con la combinación de jwks-rsa, esto puede conllevar a una omisión de autorización. Pueden estar afectados por esta vulnerabilidad si se aplican todas las condiciones siguientes: - Están usando express-jwt - No tiene **algorithms** configurados en su configuración express-jwt. - Están usando bibliotecas como jwks-rsa como el **secret**. Pueden corregir esto especificando **algorithms** en la configuración de express-jwt. Consulte GHSA vinculado por ejemplo. Esto también es corregido en la versión 6.0.0"}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"auth0","product":"express-jwt","versions":[{"version":"<= 5.3.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-285"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:auth0:express-jwt:*:*:*:*:*:node.js:*:*","versionEndIncluding":"5.3.3","matchCriteriaId":"DA2EA9DB-1370-4E0A-B443-77166B3ED3A9"}]}]}],"references":[{"url":"https://github.com/auth0/express-jwt/commit/7ecab5f8f0cab5297c2b863596566eb0c019cdef","source":"security-advisories@github.com","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/auth0/express-jwt/security/advisories/GHSA-6g6m-m6h5-w9gf","source":"security-advisories@github.com","tags":["Third Party Advisory"]},{"url":"https://github.com/auth0/express-jwt/commit/7ecab5f8f0cab5297c2b863596566eb0c019cdef","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/auth0/express-jwt/security/advisories/GHSA-6g6m-m6h5-w9gf","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}