PT-2026-97797 · Unknown · Nimble Zta
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
nimble zta versions 0.1.2 through 0.1.2
Description
Improper verification of cryptographic signatures in the Cloudflare Zero Trust authentication strategy allows an unauthenticated remote attacker to authenticate as an arbitrary Cloudflare service token. The
verify token/2 function in lib/nimble zta/cloudflare.ex incorrectly handles the result of JOSE.JWT.verify/2 by discarding the boolean verification result and returning the decoded token even after a failed signature check. An attacker can exploit this by sending a forged JSON Web Token (JWT) in the cf-access-jwt-assertion header containing the expected iss claim and seven service token claims. Because verify iss/2 reads the iss claim from the forged token without validation, the system accepts the forged claims as a legitimate authenticated identity.Recommendations
Update nimble zta to version 0.1.3.
As a temporary workaround, disable the Cloudflare authentication strategy.
Alternatively, manually reject requests if the JWT in the
cf-access-jwt-assertion header contains both the common name and type claims before calling the NimbleZTA.Cloudflare.authenticate/3 function.Exploit
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nimble Zta