VYPR

apk package

wolfi/ruby3.2-json-jwt

pkg:apk/wolfi/ruby3.2-json-jwt

Vulnerabilities (1)

  • CVE-2023-51774Dec 25, 2023
    affected < 1.16.6-r0fixed 1.16.6-r0

    The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode.