Skip to main content

Vendor/product archive

reason-jose_project / reason-jose CVEs

Beta · best-effort

1 CVEs tagged to reason-jose_project / reason-jose0 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2023-23928

Published Feb 1, 2023

reason-jose is a JOSE implementation in ReasonML and OCaml.`Jose.Jws.validate` does not check HS256 signatures. This allows tampering of JWS header and payload data if the service…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-1 of 1 CVEsPage 1 of 1