CVE-2023-51774
29.02.2024, 01:42
The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode.Enginsight
| Vendor | Product | Version |
|---|---|---|
| json-jwt_project | json-jwt | 1.16.3 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration