Upstream information
Description
The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having important severity.
SUSE Bugzilla entry: 1220727 [NEW]SUSE Security Advisories:
- openSUSE-SU-2025:0004-1, published Tue Jan 7 22:50:44 2025
List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
SUSE Package Hub 15 SP5 |
| Patchnames: openSUSE-2025-4 |
openSUSE Leap 15.5 |
| Patchnames: openSUSE-2025-4 |
SUSE Timeline for this CVE
CVE page created: Thu Feb 29 03:13:11 2024CVE page last modified: Wed Jan 8 00:59:03 2025