CVE-2016-7037
Published Jan 23, 2017The verify function in Encryption/Symmetric.php in Malcolm Fell jwt before 1.0.3 does not use a timing-safe function for hash comparison, which allows attackers to spoof signature…
Vendor/product archive
1 CVEs tagged to emarref / jwt — 0 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.
The verify function in Encryption/Symmetric.php in Malcolm Fell jwt before 1.0.3 does not use a timing-safe function for hash comparison, which allows attackers to spoof signature…