[Forgot Password]
Login  Register Subscribe

24437

 
 

132035

 
 

119400

 
 

909

 
 

96836

 
 

145

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML view JSON

CVE-2018-1000539Date: (C)2018-06-27   (M)2018-09-10


Nov json-jwt version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later.

Reference:
https://github.com/nov/json-jwt/pull/62

OVAL    1
oval:org.secpod.oval:def:603502

© SecPod Technologies