Home
CRITICAL: 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/AU:YDefault status
unaffected
Openpubkey (custom)
affected
Description
Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification.
Problem types
CWE-305: Authentication Bypass by Primary Weakness
Product status
Openpubkey (custom)
Credits
Ethan Heilman
References
github.com/openpubkey/openpubkey