{ "schema_version": "1.4.0", "id": "GHSA-xx3c-6h6w-w5rg", "modified": "2022-05-17T03:33:26Z", "published": "2022-05-17T03:33:26Z", "aliases": [ "CVE-2015-2951" ], "details": "JWT.php in F21 JWT before 2.0 allows remote attackers to bypass signature verification via crafted tokens.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-2951" }, { "type": "WEB", "url": "https://github.com/F21/jwt/commit/a327cf9052df8f9f97728ca0b5fa78a8231b79b6" }, { "type": "WEB", "url": "http://jvn.jp/en/jp/JVN06120222/index.html" }, { "type": "WEB", "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2015-000073" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/75021" } ], "database_specific": { "cwe_ids": [ "CWE-20" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2015-06-05T10:59:00Z" } }