json-jwt
JSON Web Token and its family (JSON Web Signature, JSON Web Encryption and JSON Web Key) in Ruby
Activity
- Latest release
- 1mo ago
- Total releases
- 99
- Cadence
- ~25 days
- Last 12 months
- 2
Reach
- Downloads
- 107.2M
- Stars
- 297
Details
- License
- MIT
- First release
- Sep 14, 2011
| Version | Released | |
|---|---|---|
1.17.2
patch
|
1.17.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
1.17.1
patch
|
1.17.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
1.17.0
minor
|
1.17.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
1.16.7
patch
|
1.16.7
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
1.15.3.1
patch
|
1.15.3.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.16.6
patch
|
1.16.6
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
1.16.5
patch
1 CVE
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.16.5
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
1.16.4
patch
1 CVE
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.16.4
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
1.16.3
patch
1 CVE
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.16.3
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
1.16.2
patch
1 CVE
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.16.2
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
1.16.1
patch
1 CVE
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.16.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
1.16.0
minor
1 CVE
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.16.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
1.15.3
patch
1 CVE
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.15.3
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.15.2
patch
1 CVE
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.15.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.15.1
patch
1 CVE
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.15.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.15.0
minor
1 CVE
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.15.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.14.0
minor
1 CVE
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.13.0
minor
1 CVE
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.12.0
minor
1 CVE
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.11.0
minor
1 CVE
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.10.2
patch
2 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.10.1
patch
2 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.10.0
minor
2 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.9.4
patch
2 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.9.3
patch
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.9.2
patch
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.9.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.9.0
minor
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.9.1
patch
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.8.3
patch
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.8.2
patch
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.8.1
patch
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.8.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.8.1.pre
pre
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.8.1.pre
pre
Dependencies (8)
Changelog
Compare changes
|
|
1.8.0
minor
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.8.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
1.7.2
patch
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.7.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.7.1
patch
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.7.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.7.0
minor
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.7.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.6.4
patch
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.6.4
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.6.5
patch
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.6.5
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.6.3
patch
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.6.3
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.6.2
patch
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.6.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.6.0
minor
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.6.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.6.1
patch
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.6.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.5.2
patch
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.5.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.5.1
patch
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.5.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.5.0
minor
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.5.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.4.0
minor
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.4.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.2.4
patch
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.2.4
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.3.0
minor
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.3.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.3.1
patch
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.3.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.2.3
patch
3 CVEs
CVE-2023-51774
GHSA-c8v6-786g-vjx6
Feb 29, 2024
json-jwt allows bypass of identity checks via a sign/encryption confusion attack
Medium
The json-jwt (aka JSON::JWT) gem 1.16.x before 1.16.6, 1.15.x before 1.15.3.1 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode. Affected versions
1.16.0
1.16.1
1.16.2
1.16.3
1.16.4
1.16.5
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
+ 81 more Show less
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.3.1
1.16.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-18848
GHSA-cff7-6h4q-q5pj
Nov 14, 2019
JSON-jwt Gem lacked element count during splitting of JWE string
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.1.0
0.1.1
0.1.2
0.1.3
+ 67 more Show less
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.10.0
1.10.1
1.10.2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.11.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000539
GHSA-mj4x-wcxf-hm8x
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
The json-jwt rubygem version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability in Decryption of AES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a authentication tag. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in 1.9.4 and later. Affected versions
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.7.0
0.7.0.alpha
0.7.0.alpha2
0.7.1
+ 36 more Show less
0.8.0
0.8.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.1.pre
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.9.4
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.2.3
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|