Security Advisory

CVE-2024-33531

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-04-24 00:00:00
Last updated 2024-08-02 02:36:03
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

cdbattags lua-resty-jwt 0.2.3 allows attackers to bypass all JWT-parsing signature checks by crafting a JWT with an enc header with the value A256GCM.