Количество 6
Количество 6
CVE-2023-51774
The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode.
CVE-2023-51774
The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode.
CVE-2023-51774
The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode.
CVE-2023-51774
The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypa ...
GHSA-c8v6-786g-vjx6
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
openSUSE-SU-2025:0004-1
Security update for rubygem-json-jwt
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-51774 The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. | CVSS3: 8.4 | 0% Низкий | почти 2 года назад | |
CVE-2023-51774 The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. | CVSS3: 6.5 | 0% Низкий | почти 2 года назад | |
CVE-2023-51774 The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. | CVSS3: 8.4 | 0% Низкий | почти 2 года назад | |
CVE-2023-51774 The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypa ... | CVSS3: 8.4 | 0% Низкий | почти 2 года назад | |
GHSA-c8v6-786g-vjx6 json-jwt allows bypass of identity checks via a sign/encryption confusion attack | 0% Низкий | почти 2 года назад | ||
openSUSE-SU-2025:0004-1 Security update for rubygem-json-jwt | около 1 года назад |
Уязвимостей на страницу