{"schema_version":"1.7.3","id":"GHSA-675f-rq2r-jw82","published":"2025-01-09T17:23:43Z","modified":"2025-01-09T20:12:30.168789Z","aliases":["CVE-2025-22149","GO-2025-3376"],"summary":"JWK Set's HTTP client only overwrites and appends JWK to local cache during refresh","details":"### Impact\nThe project's provided HTTP client's local JWK Set cache should do a full replacement when the goroutine refreshes the remote JWK Set. The current behavior is to overwrite or append. This is a security issue for use cases that utilize the provided auto-caching HTTP client and where key removal from a JWK Set is equivalent to revocation.\n\nExample attack scenario:\n1. An attacker has stolen the private key for a key published in JWK Set.\n2. The publishers of that JWK Set remove that key from the JWK Set.\n3. Enough time has passed that the program using the auto-caching HTTP client found in `github.com/MicahParks/jwkset` v0.5.0-v0.5.21 has elapsed its `HTTPClientStorageOptions.RefreshInterval` duration, causing a refresh of the remote JWK Set.\n4. The attacker is signing content (such as JWTs) with the stolen private key and the system has no other forms of revocation.\n\n### Patches\nThe affected auto-caching HTTP client was added in version `v0.5.0` and fixed in `v0.6.0`. Upgrade to `v0.6.0` or later.\n\n### Workarounds\nThe only workaround would be to remove the provided auto-caching HTTP client and replace it with a custom implementation. This involves setting the `HTTPClientStorageOptions.RefreshInterval` to zero (or not specifying the value). Upgrade to `v0.6.0` is advised.\n\n### References\nPlease see the tracking issue on GitHub for additional details: https://github.com/MicahParks/jwkset/issues/40\n","affected":[{"package":{"name":"github.com/MicahParks/jwkset","ecosystem":"Go","purl":"pkg:golang/github.com/MicahParks/jwkset"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.5.0"},{"fixed":"0.6.0"}]}],"database_specific":{"last_known_affected_version_range":"<= 0.5.21","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-675f-rq2r-jw82/GHSA-675f-rq2r-jw82.json"}}],"references":[{"type":"WEB","url":"https://github.com/MicahParks/jwkset/security/advisories/GHSA-675f-rq2r-jw82"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-22149"},{"type":"WEB","url":"https://github.com/MicahParks/jwkset/issues/40"},{"type":"WEB","url":"https://github.com/MicahParks/jwkset/pull/41"},{"type":"WEB","url":"https://github.com/MicahParks/jwkset/commit/01db49a90f7f20c7fb39a699a2f19a7a5f379ed3"},{"type":"PACKAGE","url":"https://github.com/MicahParks/jwkset"}],"database_specific":{"cwe_ids":["CWE-672"],"github_reviewed":true,"github_reviewed_at":"2025-01-09T17:23:43Z","nvd_published_at":"2025-01-09T18:15:30Z","severity":"LOW"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"}]}