jwt-scala 1.2.2 and earlier fails to verify token signatures correctly which may lead to an attacker being able to pass specially crafted JWT data as a correctly signed token.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| io.really:jwt-scala(Maven) | 0 | N/A | N/A |
CVSS Metrics