VDB
Sign up
HIGH7.5

GHSA-xm5f-hc9r-76f3

PHP JOSE Library by Gree Inc. Uses a Broken or Risky Cryptographic Algorithm

Quick fix

GHSA-xm5f-hc9r-76f3 — gree/jose: upgrade to the fixed version with the command below.

composer require gree/jose:^2.2.1

Details

The PHP JOSE Library by Gree Inc. prior to 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/gree/jose
Introduced in: 0Fixed in: 2.2.1
Fixcomposer require gree/jose:^2.2.1

References