HashiCorp Hermes Authentication Bypass Vulnerability via Improper JWT Validation in AWS ALB Mode
Vulnerability
A vulnerability allowing authentication bypass has been identified in HashiCorp Hermes versions prior to 0.4.0. The issue arises from improper validation of JSON Web Tokens (JWTs) when using AWS Application Load Balancer (ALB) for authentication. This flaw could enable a party with direct access to the Hermes application server to bypass authentication controls. The vulnerability, known as 'ALBeast', was addressed in Hermes version 0.5.0.
Impact
Exploitation of this vulnerability could lead to unauthorized access by bypassing authentication mechanisms, allowing users to gain access to resources or functionalities without proper credentials.
Remediation
Users of HashiCorp Hermes should upgrade to version 0.5.0 or later.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
