Auth0 / Jsonwebtoken
4 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-23539 | jsonwebtoken unrestricted key type could lead to legacy keys usage | HIGH | 8.1 | Dec 22, 2022 |
| CVE-2022-23540 | jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify() | HIGH | 7.6 | Dec 22, 2022 |
| CVE-2022-23541 | jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC | MEDIUM | 6.3 | Dec 22, 2022 |
| CVE-2015-9235 | nodejs-jsonwebtoken: verification step bypass with an altered token | CRITICAL | 9.8 | May 29, 2018 |
Showing 1 to 4 of 4 CVEs