The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Json-jwt | Json-jwt_project | * | 1.11.0 (excluding) |
Ruby-json-jwt | Ubuntu | bionic | * |
Ruby-json-jwt | Ubuntu | disco | * |
Ruby-json-jwt | Ubuntu | eoan | * |
Ruby-json-jwt | Ubuntu | esm-apps/bionic | * |
Ruby-json-jwt | Ubuntu | trusty | * |
Ruby-json-jwt | Ubuntu | upstream | * |