PKSA-237v-kv6c-dpkr Security Advisory
-
[HIGH] RSA1_5 (RSAES-PKCS1-v1_5) decryption lacks implicit rejection, exposing a Bleichenbacher/Marvin padding oracle
PKSA-237v-kv6c-dpkr GHSA-3prj-6hqw-cm82
Affected package: web-token/jwt-library
Affected version: <3.4.10|>=4.0.0,<4.0.7|>=4.1.0,<4.1.7
Reported by:
GitHub, FriendsOfPHP/security-advisories