▓▓▓ ⚠️
IF YOU USE NGINX / OPENRESTY — PLEASE SHARE
⚠️ ▓▓▓
Update on that CVE-2024-33531 thread: I traced the git blame, and the vulnerability wasn't my code.
The flawed JWE routing logic was introduced by community contributors in 2016 and 2020 in the original SkyLothar/lua-resty-jwt before I ever forked it. I just inherited the bug and then wasn't around to fix it when it was reported.
Post summary
The author clarifies that the CVE‑2024‑33531 flaw was introduced by community contributors and not their code, providing a brief technical detail but no PoC, exploit, patch, or active exploitation information.
Confession: I forked an open-source JWT library a few years back, not really knowing what I was getting into in terms of maintenance. Then I abandoned it for... a while. Long enough for a critical CVE to sit unfixed (CVE-2024-33531 — auth bypass via header confusion, oops).
This library has 8.4M+ downloads. Cool cool cool.
The good news: it's fixed in 0.2.4, and I just shipped v0.3.0 of lua-resty-jwt with full IANA JOSE algorithm coverage.
HS256-512, RS256-512, ES256-512, PS256-512, Ed25519, Ed448, every JWE key management algo (RSA-OAEP, ECDH-ES, AES-KW, AES-GCM-KW, PBES2), all six content encryption modes.
Shoutout to Nils Emmerich (@ERNW_ITSec) for responsibly reporting the vuln while I was off being a terrible maintainer. His excellent writeup: http://insinuator.net/2023/10/lua-resty-jwt-authentication-bypass/
Advisory: http://github.com/cdbattags/lua-resty-jwt/security/advisories/GHSA-9r96-mgg4-2jf3
Release: http://github.com/cdbattags/lua-resty-jwt/releases/tag/v0.3.0
Post summary
The post announces that a critical authentication bypass (CVE‑2024‑33531) in lua‑resty‑jwt has been fixed in version 0.2.4, with a new release 0.3.0 providing full algorithm coverage, and references a writeup that likely contains a PoC.
We're doing great out there
Friendly reminder, anything less than 0.2.4-1 has a nasty CVE
https://www.cve.org/CVERecord?id=CVE-2024-33531 https://t.co/5WEZA73F0l
Post summary
The tweet alerts that any version below 0.2.4-1 of the software is affected by CVE-2024-33531, linking to the CVE record, but offers no additional technical, exploitation, or patching details.