Json-Jwt
Json-Jwt Project · 3 CVEs
CVE-2023-51774
HIGH
json-jwt: bypass of identity checks via a sign/encryption confusion attack
Dec 25, 2023
CVE-2019-18848
HIGH
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string.
Nov 12, 2019
CVE-2018-1000539
MEDIUM
Nov json-jwt version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerabi…
Jun 26, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2023-51774 | json-jwt: bypass of identity checks via a sign/encryption confusion attack | HIGH | 0.23% | Dec 25, 2023 |
| CVE-2019-18848 | The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. | HIGH | 1.26% | Nov 12, 2019 |
| CVE-2018-1000539 | Nov json-jwt version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted… | MEDIUM | 0.78% | Jun 26, 2018 |
Showing 1 to 3 of 3 CVEs