CVE-2015-2964 Information

Description

NAMSHI | JOSE 5.0.0 and earlier allows remote attackers to bypass signature verification via crafted tokens in a JSON Web Tokens (JWT) header.

Reference

http://jvn.jp/en/jp/JVN25336719/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2015-000090 http://www.securityfocus.com/bid/75423

Share on: