VDB
Sign up
MEDIUM

GHSA-c8v6-786g-vjx6

json-jwt allows bypass of identity checks via a sign/encryption confusion attack

Quick fix

GHSA-c8v6-786g-vjx6 — json-jwt: upgrade to the fixed version with the command below.

bundle update json-jwt

Details

The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/json-jwt
Introduced in: 1.16.0Fixed in: 1.16.6
Fixbundle update json-jwt
RubyGems/json-jwt
Introduced in: 0Fixed in: 1.15.3.1
Fixbundle update json-jwt

References