Description
When attempting to allow authentication mode `try` in hapi, hapi-auth-jwt2 version 5.1.1 introduced an issue whereby people could bypass authentication.
Remediation
References
https://github.com/dwyl/hapi-auth-jwt2/issues/111
https://github.com/dwyl/hapi-auth-jwt2/pull/112
https://nodesecurity.io/advisories/81
Related Vulnerabilities
CVE-2023-2479 Vulnerability in npm package appium-desktop
CVE-2014-0095 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2020-17532 Vulnerability in maven package org.apache.servicecomb:foundation-config
CVE-2021-41165 Vulnerability in maven package org.webjars.bowergithub.ckeditor:ckeditor4
CVE-2023-25827 Vulnerability in maven package net.opentsdb:opentsdb