PT-2019-15698 · Ruby · Json-Jwt

Nov

·

Publicado

2019-11-12

·

Atualizado

2025-01-07

·

CVE-2019-18848

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions json-jwt gem versions prior to 1.11.0
Description The issue is related to the json-jwt gem for Ruby, where it lacks an element count during the splitting of a JWE string. This lack of element count can lead to potential security issues.
Recommendations For versions prior to 1.11.0, update to version 1.11.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of JWE strings until the update is applied.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-18848
DLA-2390-1
GHSA-CFF7-6H4Q-Q5PJ
OPENSUSE-SU-2025:0004-1

Produtos afetados

Json-Jwt