CVE-2019-18848

Published
View on NVD ↗
CVSS v3
7.5
HIGH
CVSS v2
5
MEDIUM
Affected
1
PROJECT

Description

The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string.

JSON Web Token and its family (JSON Web Signature, JSON Web Encryption and JSON Web Key) in Ruby
GitHubGitHub
298