Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h533-5v22-8vcp

Опубликовано: 15 мая 2024
Источник: github
Github: Прошло ревью

Описание

firebase/php-jwt: "None" Algorithm treated as valid on tokens

Several widely-used JSON Web Token (JWT) libraries, including node-jsonwebtoken, pyjwt, namshi/jose, php-jwt, and jsjwt, are affected by critical vulnerabilities that could allow attackers to bypass the verification step when using asymmetric keys (RS256, RS384, RS512, ES256, ES384, ES512).

Пакеты

Наименование

firebase/php-jwt

composer
Затронутые версииВерсия исправления

< 2.0.0

2.0.0