Vulnerabilities (CVE)

Filtered by vendor Connect2id Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-12973 1 Connect2id 1 Nimbus Jose\+jwt 2019-10-03 4.3 MEDIUM 3.1 LOW
Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackers to conduct a padding oracle attack.