CVE-2016-5431

Severity CVSS v4.0:
Pending analysis
Type:
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Publication date:
07/08/2019
Last modified:
03/03/2023

Description

The PHP JOSE Library by Gree Inc. before version 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:php_jose_project:php_jose:*:*:*:*:*:*:*:* 2.2.1 (excluding)