Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-1000539

Опубликовано: 26 июн. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 5
CVSS3: 5.3

Описание

Nov json-jwt version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

esm-apps/bionic

needed

esm-apps/focal

not-affected

1.11.0-1
esm-apps/jammy

not-affected

esm-apps/noble

not-affected

esm-infra-legacy/trusty

DNE

focal

not-affected

1.11.0-1
groovy

not-affected

hirsute

not-affected

Показывать по

5 Medium

CVSS2

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
больше 7 лет назад

Nov json-jwt version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later.

CVSS3: 5.3
debian
больше 7 лет назад

Nov json-jwt version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper ...

CVSS3: 5.3
github
больше 7 лет назад

Json-jwt did not verify the cryptographic signature for data

5 Medium

CVSS2

5.3 Medium

CVSS3