8.4
CVE-2023-51774
- EPSS 0.23%
- Veröffentlicht 29.02.2024 01:42:05
- Zuletzt bearbeitet 08.05.2025 22:48:00
- Erkennungen
The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Json-jwt Project ≫ Json-jwt Version 1.16.3 SwPlatform ruby
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.141 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 8.4 | 2.5 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
https://github.com/P3ngu1nW/CVE_Request/blob/main/novjson-jwt.md