OpenPubkey
cpe:2.3:a:openpubkey:openpubkey:*:*:*:*:*:*:*
- < 0.10.0
A vulnerability exists in the OpenPubkey library in versions prior to 0.10.0, allowing a specially crafted JSON Web Signature (JWS) to bypass signature verification. This issue arises from the library's handling of JWS signatures, which can be exploited to undermine the integrity of the signature verification process.
Exploitation of this vulnerability allows for the bypassing of signature verification in JWS, potentially leading to unauthorized actions or the acceptance of fraudulent signatures.
Users can upgrade to OpenPubkey version 0.10.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.