Description
The PHP JOSE Library by Gree Inc. before version 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5819 | The PHP JOSE Library by Gree Inc. before version 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens. |
Github GHSA |
GHSA-xm5f-hc9r-76f3 | PHP JOSE Library by Gree Inc. Uses a Broken or Risky Cryptographic Algorithm |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T01:01:00.112Z
Reserved: 2016-06-10T00:00:00.000Z
Link: CVE-2016-5431
No data.
Status : Modified
Published: 2019-08-07T15:15:11.783
Modified: 2024-11-21T02:54:17.953
Link: CVE-2016-5431
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA