CVE-2023-51774
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
EPSS 0.23%
Description
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode.
How to fix CVE-2023-51774
To remediate CVE-2023-51774, upgrade the affected package to a fixed version below.
- RubyGems/json-jwt—upgrade to 1.16.6 or later
Is CVE-2023-51774 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 1.16.0, < 1.16.6