VDB

CVE-2023-51774

CVE-2023-51774 PUBLISHED CVSS 8.399999618530273 HIGH

json-jwt allows bypass of identity checks via a sign/encryption confusion attack

EPSS 0.01% · 1.4th percentile

Risk Scores

CVSS v3.1
8.399999618530273
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.01%
1.4th percentile

Affected Products

VendorProductVersions
n/an/a*, n/a
RubyGemsjson-jwt0, 1.16.0, 0
json-jwt_projectjson-jwt1.16.3, 1.16.3
json-jwt_projectjson-jwt1.16.3, 1.16.3

Timeline

  • Dec 25, 2023 CVE Published
  • Dec 26, 2023 EPSS Score
  • Jan 24, 2024 EPSS Score
  • Feb 22, 2024 EPSS Score
  • Feb 29, 2024 PoC Published
  • Mar 21, 2024 EPSS Score
  • Apr 19, 2024 EPSS Score
  • May 18, 2024 EPSS Score
  • Jun 16, 2024 EPSS Score
  • Jul 14, 2024 EPSS Score
  • Aug 12, 2024 EPSS Score
  • Sep 10, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›