CVE-2023-48238: json-web-token library is vulnerable to a JWT algorithm confusion attack
(updated )
The json-web-token library is vulnerable to a JWT algorithm confusion attack.
References
- github.com/advisories/GHSA-4xw9-cx39-r355
- github.com/joaquimserafim/json-web-token/blob/acf6a462471e1b14187eb77414e9161b8b7bff7e/index.js
- github.com/joaquimserafim/json-web-token/commit/b6e56b1346f48432d29133c76b65222ad93956b7
- github.com/joaquimserafim/json-web-token/security/advisories/GHSA-4xw9-cx39-r355
- nvd.nist.gov/vuln/detail/CVE-2023-48238
Code Behaviors & Features
Detect and mitigate CVE-2023-48238 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →