cdbattags lua-resty-jwt 0.2.3 allows attackers to bypass...
High severity
Unreviewed
Published
Apr 24, 2024
to the GitHub Advisory Database
•
Updated Jul 3, 2024
Description
Published by the National Vulnerability Database
Apr 24, 2024
Published to the GitHub Advisory Database
Apr 24, 2024
Last updated
Jul 3, 2024
cdbattags lua-resty-jwt 0.2.3 allows attackers to bypass all JWT-parsing signature checks by crafting a JWT with an enc header with the value A256GCM.
References