Bugzilla – Bug 1220727
VUL-0: CVE-2023-51774: rubygem-json-jwt: JWE can sometimes be used to bypass JSON:JWT.decode
Last modified: 2024-07-04 08:45:05 UTC
The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-51774 https://www.cve.org/CVERecord?id=CVE-2023-51774 https://github.com/P3ngu1nW/CVE_Request/blob/main/novjson-jwt.md
Only Backports need this fix: openSUSE:Factory rubygem-json-jwt-1.16.5 openSUSE:Backports:SLE-15-SP5 rubygem-json-jwt-1.9.1 openSUSE:Backports:SLE-15-SP6 rubygem-json-jwt-1.9.1
This is an autogenerated message for OBS integration: This bug (1220727) was mentioned in https://build.opensuse.org/request/show/1185337 Backports:SLE-15-SP6 / rubygem-json-jwt https://build.opensuse.org/request/show/1185338 Backports:SLE-15-SP5 / rubygem-json-jwt