apk package
chainguard/ruby3.2-json-jwt
pkg:apk/chainguard/ruby3.2-json-jwt
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-51774 | — | < 1.16.6-r0 | 1.16.6-r0 | Dec 25, 2023 | The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. |
- CVE-2023-51774Dec 25, 2023affected < 1.16.6-r0fixed 1.16.6-r0
The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode.