It was discovered that ruby-jwt, a JSON Web Token implementation in Ruby, insufficiently validated the HMAC of some tokens. https://security-tracker.debian.org/tracker/DSA-6547-1 Weiterlesen: DSA-6547-1 ruby-jwt - security update
Intelligence View
⚡ tsecurity.de Intelligence
DSA-6547-1 ruby-jwt - security update
It was discovered that ruby-jwt, a JSON Web Token implementation in Ruby, insufficiently validated the HMAC of some tokens.…
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!
Powered by tsecurity.de
tsecurity.de Hub
Intelligence Digest — kostenlos Täglich die wichtigsten Security-News · jederzeit abbestellbar
Community Rating & Social Proof
⭐ Leser-Wertung
–
Ø / 5.0
★★★★★
Noch keine Leser-Bewertungen
War diese Seite hilfreich?
0
Powered by tsecurity.de
tsecurity.de Hub
Verwandte Story-Cluster & Quellen (Vektor-KI)
17 Quellen
CVE-2026-87869 | stepasyuk Filter Everything Plugin up to 1.9.6 on WordPress flrt_elementor_load_more_anchor REQUEST_URI cross site scripting (EUVD-2026-96060)
16 weitere Quellen
VVulDB Updatesvor 1 Std.CVE-2026-97630 | Foliovision FV Flowplayer Video Player Plugin up to 7.5.54.7212 on WordPress Shortcode cross site scripting (EUVD-2026-96059) VVulDB Updatesvor 1 Std.CVE-2026-5727 | Elementor Hello Plus Plugin up to 1.7.7 on WordPress authorization (EUVD-2026-96058) VVulDB Updatesvor 1 Std.CVE-2026-101324 | wpmanageninja Fluent Forms Plugin up to 6.2.14 on WordPress SmartCode NAME cross site scripting (EUVD-2026-96056) VVulDB Updatesvor 1 Std.CVE-2026-102401 | codename065 Download Manager Plugin up to 3.3.71 on WordPress login-form.php regurl cross site scripting (EUVD-2026-96057) VVulDB Updatesvor 1 Std.CVE-2026-103889 | expivi 3D Product Configurator Plugin up to 2.16.2 on WordPress Image Processing wp_loaded xpv_image missing authentication (EUVD-2026-96055) VVulDB Updatesvor 1 Std.CVE-2026-104993 | paoltaia GeoDirectory Plugin up to 2.8.188 on WordPress email cross site scripting (EUVD-2026-96054)
+10
13 Quellen
CVE-2026-78669 | Go http HTTP 2 amplification (ID 847186 / EUVD-2026-95426)
12 weitere Quellen
VVulDB Updatesvor 2 Std.CVE-2026-94440 | Google Go up to 1.26.8/1.27.1 net textproto mime multipart allocation of resources (EUVD-2026-95423 / WID-SEC-2026-3841) VVulDB Updatesvor 2 Std.CVE-2026-94444 | cmd go up to 1.26.8/1.27.1 GOMODPROXY integrity check (EUVD-2026-95417 / WID-SEC-2026-3841) VVulDB Updatesvor 2 Std.CVE-2026-94447 | Google cmd/go up to 1.26.8/1.27.1 GOMODPROXY go.sum integrity check (EUVD-2026-95418 / WID-SEC-2026-3841) VVulDB Updatesvor 2 Std.CVE-2026-97031 | Google crypto tls up to 1.26.8/1.27.1 Packet amplification (EUVD-2026-95422 / WID-SEC-2026-3841) VVulDB Updatesvor 2 Std.CVE-2026-97030 | Go html/template up to 1.26.8/1.27.1 Template cross site scripting (EUVD-2026-95416 / WID-SEC-2026-3841) VVulDB Updatesvor 2 Std.CVE-2026-94448 | Google html/template up to 1.26.8/1.27.1 Template Literal Expression cross site scripting (EUVD-2026-95415 / WID-SEC-2026-3841)
+6
11 Quellen
CVE-2022-46137 | AeroCMS 0.0.1 pathname traversal (EUVD-2022-48975)
10 weitere Quellen
VVulDB Updatesvor 3 Std.CVE-2022-46139 | TP-Link TL-WR940N V4 up to 3.16.9 Firmware denial of service (EUVD-2022-48977) VVulDB Updatesvor 3 Std.CVE-2022-46140 | Siemens SCALANCE ZIP File risky encryption (ssa-413565 / EUVD-2022-48978) VVulDB Updatesvor 3 Std.CVE-2022-46142 | Siemens SCALANCE CLI User Password password recoverable (ssa-413565 / EUVD-2022-48980) VVulDB Updatesvor 3 Std.CVE-2022-46143 | Siemens SCALANCE TFTP uninitialized pointer (ssa-413565 / EUVD-2022-48981) VVulDB Updatesvor 4 Std.CVE-2022-46123 | oretnom23 Helmet Store Showroom Site 1.0 manage_category.php id sql injection (EUVD-2022-48961) VVulDB Updatesvor 4 Std.CVE-2022-46125 | oretnom23 Helmet Store Showroom Site 1.0 manage_client id sql injection (EUVD-2022-48963)
+4
Mehr aus dieser Kategorie
Blättern: Pfeiltasten [ ← ] [ → ] · Tasten j / k · mobil: Wischen
HAND-OFF
Auf Smartphone übergeben (ADVISORY)
Scannen Sie den QR-Code mit der Smartphone-Kamera für sofortigen mobilen Zugriff:
https://tsecurity.de/de/4262370/linux-tipps-hardening/dsa-6547-1-ruby-jwt-security-update/