PT-2025-32312 · Ruby-Jwt · Ruby-Jwt
Discription

Name of the Vulnerable Software and Affected Versions: ruby-jwt version 3.0.0.beta1 Description: ruby-jwt v3.0.0.beta1 contains weak encryption. The supplier notes that key size is not enforced by the library itself, and restrictions imposed by recent versions of OpenSSL may apply to users of the gem. Recommendations: At the moment, there is no information about a newer version that contains a fix for this…Read More
References
Back to Main