Skip to main content

Vendor/product archive

emarref / jwt CVEs

Beta · best-effort

1 CVEs tagged to emarref / jwt0 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2016-7037

Published Jan 23, 2017

The verify function in Encryption/Symmetric.php in Malcolm Fell jwt before 1.0.3 does not use a timing-safe function for hash comparison, which allows attackers to spoof signature…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-1 of 1 CVEsPage 1 of 1