CVE-2017-10862

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
12/10/2017
Last modified:
20/04/2025

Description

jwt-scala 1.2.2 and earlier fails to verify token signatures correctly which may lead to an attacker being able to pass specially crafted JWT data as a correctly signed token.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:really:jwt-scala:*:*:*:*:*:*:*:* 1.2.2 (including)