PHP JOSE Library by Gree Inc. Uses a Broken or Risky Cryptographic Algorithm
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Mar 11, 2023
Description
Published by the National Vulnerability Database
Aug 7, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Mar 3, 2023
Last updated
Mar 11, 2023
The PHP JOSE Library by Gree Inc. prior to 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens.
References