WatchGuard Firmware 12.11.6 is it affected by the "pac4j-jwt JwtAuthenticator Authentication Bypass"

Hi Community,

I just wanted to ask if the Watchguard firmware version 12.11.6 is affected by this exploit "pac4j-jwt JwtAuthenticator Authentication Bypass"

https://www.vulncheck.com/advisories/pac4j-jwt-jwtauthenticator-authentication-bypass

Kindly advise what is the workaround.

Answers

  • james.carsonjames.carson Moderator, WatchGuard Representative

    Hi @Lapu_Lapu
    WatchGuard doesn't utilize the JwtAuthenticator component that this vulnerability is posted for, so it would not be applicable to any of our products at this time.

    -James Carson
    WatchGuard Customer Support

Sign In to comment.