jwtk kayıtları
jwtk üreticisine ait 2 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %50
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tüm kayıtlar
2 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
27İzleyin | CVE-2024-31033İstismar yok | JJWT (aka Java JWT) through 0.12.5 ignores certain characters and thus a user might falsely conclude that they have a strong key. | Orta6,8 | — | %0,8 | 31 Mar 2024 |
23İzleyin | CVE-2024-34273İstismar yok | njwt up to v0.4.0 was discovered to contain a prototype pollution in the Parser.prototype.parse method.CWE-1321 | Orta5,9 | — | %0,5 | 16 May 2024 |
- CVE-2024-3103327İzleyin
JJWT (aka Java JWT) through 0.12.5 ignores certain characters and thus a user might falsely conclude that they have a strong key.
OrtaCVSS 6,8İstismar yokEPSS %131 Mar 2024
- CVE-2024-3427323İzleyin
njwt up to v0.4.0 was discovered to contain a prototype pollution in the Parser.prototype.parse method.
OrtaCVSS 5,9İstismar yokEPSS %016 May 2024