The PHP JOSE Library by Gree Inc. before version 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2019-08-07T15:13:47

Updated: 2019-08-08T15:32:17

Reserved: 2016-06-10T00:00:00


Link: CVE-2016-5431

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-08-07T15:15:11.783

Modified: 2023-03-03T15:53:43.550


Link: CVE-2016-5431

JSON object: View

cve-icon Redhat Information

No data.

CWE