The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode.
This Cyber News was published on www.tenable.com. Publication date: Thu, 29 Feb 2024 10:51:03 +0000