HIGH
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string
Published Nov 12, 2019
7.5
HIGHCVSS 3.1
EPSS 1.26%
Description
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string.
Affected products
No data.
Configuration 1
- < 1.11.0
Configuration 2
- 9.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://github.com/advisories/GHSA-cff7-6h4q-q5pj Advisory
- https://github.com/nov/json-jwt/commit/ada16e772906efdd035e3df49cb2ae372f0f948a x_refsource_MISCPatch
- https://github.com/nov/json-jwt/compare/v1.10.2...v1.11.0 x_refsource_MISCPatch
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/json-jwt/CVE-2019-18848.yml
- https://lists.debian.org/debian-lts-announce/2020/10/msg00001.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-18848
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-cff7-6h4q-q5pj | Advisory | |
| https://github.com/nov/json-jwt/commit/ada16e772906efdd035e3df49cb2ae372f0f948a | x_refsource_MISCPatch | |
| https://github.com/nov/json-jwt/compare/v1.10.2...v1.11.0 | x_refsource_MISCPatch | |
| https://github.com/rubysec/ruby-advisory-db/blob/master/gems/json-jwt/CVE-2019-18848.yml | ||
| https://lists.debian.org/debian-lts-announce/2020/10/msg00001.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-18848 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 12, 2019
Updated Aug 5, 2024
Reserved Nov 11, 2019
Link CVE-2019-18848
CISA Vulnrichment
GHSA-CFF7-6H4Q-Q5PJ Updated n/a