Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mj4x-wcxf-hm8x

Опубликовано: 31 июл. 2018
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Json-jwt did not verify the cryptographic signature for data

The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later.

Пакеты

Наименование

json-jwt

rubygems
Затронутые версииВерсия исправления

>= 0.5.1, < 1.9.4

1.9.4

EPSS

Процентиль: 34%
0.0014
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 7 лет назад

Nov json-jwt version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later.

CVSS3: 5.3
nvd
больше 7 лет назад

Nov json-jwt version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later.

CVSS3: 5.3
debian
больше 7 лет назад

Nov json-jwt version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper ...

EPSS

Процентиль: 34%
0.0014
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-347