GO-2022-0380

The AccountClaims.IsRevoked and Export.IsRevoked functions improperly validate expired credentials using the current system time rather than the issue time of the JWT to be tested. These functions can ...

Continue Reading
[SECURITY] Fedora 35 Update: golang-github-jwt-3.2.2-3.fc35

A go implementation of JSON Web Tokens. Supports the parsing and verification, as well as the generation and signing of JWTs.Read More ...

Continue Reading
[SECURITY] Fedora 35 Update: golang-github-dgrijalva-jwt-3.2.0-11.fc35

Golang implementation of json web tokens (jwt).Read More ...

Continue Reading
SUSE SLES15 Security Update : python-PyJWT (SUSE-SU-2022:2403-1)

The remote SUSE Linux SLES15 host has packages installed that are affected by a vulnerability as referenced in the SUSE- SU-2022:2403-1 advisory. - PyJWT is a Python implementation of RFC 7519. PyJW ...

Continue Reading
SUSE SLES12 Security Update : python-PyJWT (SUSE-SU-2022:2401-1)

The remote SUSE Linux SLES12 host has packages installed that are affected by a vulnerability as referenced in the SUSE- SU-2022:2401-1 advisory. - PyJWT is a Python implementation of RFC 7519. PyJW ...

Continue Reading
SUSE SLED15 / SLES15 Security Update : python-PyJWT (SUSE-SU-2022:2402-1)

The remote SUSE Linux SLED15 / SLES15 host has a package installed that is affected by a vulnerability as referenced in the SUSE-SU-2022:2402-1 advisory. - PyJWT is a Python implementation of RFC 75 ...

Continue Reading
Open-Source API Firewall Unveils New Feature: Default Deny Lists for Compromised API Tokens and Cookies

Discovering and securing any API is one of the most difficult challenges for developers. The[ API security]() landscape is constantly evolving, with new threats and vulnerabilities emerging at a rapid ...

Continue Reading
Improper Verification of Cryptographic Signature in Nimbus JOSE+JWT

Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve, which allows attackers to conduct an Invalid Curve Attack ...

Continue Reading

Back to Main

Subscribe for the latest news: