VDB
CVE-2023-51774
CVE-2023-51774
PUBLISHED
CVSS 8.399999618530273 HIGH
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
EPSS 0.01% · 1.4th percentile
Risk Scores
CVSS v3.1
8.399999618530273
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.01%
1.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | *, n/a |
| RubyGems | json-jwt | 0, 1.16.0, 0 |
| json-jwt_project | json-jwt | 1.16.3, 1.16.3 |
| json-jwt_project | json-jwt | 1.16.3, 1.16.3 |
Timeline
- Dec 25, 2023 CVE Published
- Dec 26, 2023 EPSS Score
- Jan 24, 2024 EPSS Score
- Feb 22, 2024 EPSS Score
- Feb 29, 2024 PoC Published
- Mar 21, 2024 EPSS Score
- Apr 19, 2024 EPSS Score
- May 18, 2024 EPSS Score
- Jun 16, 2024 EPSS Score
- Jul 14, 2024 EPSS Score
- Aug 12, 2024 EPSS Score
- Sep 10, 2024 EPSS Score
References
- https://github.com/P3ngu1nW/CVE_Request/blob/main/novjson-jwt.md url
- https://nvd.nist.gov/vuln/detail/CVE-2023-51774 advisory
- https://github.com/nov/json-jwt/issues/120 url
- https://github.com/nov/json-jwt/issues/121 url
- https://github.com/nov/json-jwt/commit/593ea8bcaf2629048bad8c036191f2da0a2e713c url
- https://github.com/nov/json-jwt/commit/9c4d842a9465bd7960570ca326c3de79b4abc9d0 url
- https://github.com/nov/json-jwt package
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/json-jwt/CVE-2023-51774.yml url