[MAVEN:GHSA-9PXM-8G95-Q5XR] Insufficient Data Verification in io.really:jwt-scala

Severity Moderate
Affected Packages 1
CVEs 1

jwt-scala 1.2.2 and earlier fails to verify token signatures correctly which may lead to an attacker being able to pass specially crafted JWT data as a correctly signed token.

Package Affected Version
pkg:maven/io.really/jwt-scala <= 1.2.2
ID
MAVEN:GHSA-9PXM-8G95-Q5XR
Severity
moderate
URL
https://github.com/advisories/GHSA-9pxm-8g95-q5xr
Published
2022-05-17T00:28:41
(2 years ago)
Modified
2023-01-30T05:00:49
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/io.really/jwt-scala io.really jwt-scala <= 1.2.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...