VDB
CVE-2023-51774
CVE-2023-51774
PUBLISHED
CVSS 8.399999618530273 HIGH
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
EPSS 0.23% · 13.9th percentile
Risk Scores
CVSS 3.1
8.399999618530273
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.23%
13.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | *, n/a |
| RubyGems | json-jwt | 0, 1.16.0, 0 |
| json-jwt_project | json-jwt | 1.16.3, 1.16.3 |
| json-jwt_project | json-jwt | 1.16.3, 1.16.3 |
Timeline
- Dec 25, 2023 CVE Published
- Dec 26, 2023 EPSS Score
- Jan 24, 2024 EPSS Score
- Feb 22, 2024 EPSS Score
- Feb 29, 2024 PoC Published
- Mar 22, 2024 EPSS Score
- Apr 19, 2024 EPSS Score
- May 18, 2024 EPSS Score
- Jun 16, 2024 EPSS Score
- Jul 15, 2024 EPSS Score
- Aug 13, 2024 EPSS Score
- Sep 11, 2024 EPSS Score
References
- https://github.com/P3ngu1nW/CVE_Request/blob/main/novjson-jwt.md url
- https://github.com/nov/json-jwt/commit/593ea8bcaf2629048bad8c036191f2da0a2e713c url
- https://github.com/nov/json-jwt package
- https://nvd.nist.gov/vuln/detail/CVE-2023-51774 advisory
- https://github.com/nov/json-jwt/issues/120 url
- https://github.com/nov/json-jwt/issues/121 url
- https://github.com/nov/json-jwt/commit/9c4d842a9465bd7960570ca326c3de79b4abc9d0 url
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/json-jwt/CVE-2023-51774.yml url