Description
JPaseto before 0.3.0 generates weak hashes when using v2.local tokens.
Remediation
References
https://github.com/paseto-toolkit/jpaseto/releases/tag/jpaseto-0.3.0
Related Vulnerabilities
CVE-2021-3827 Vulnerability in maven package org.keycloak:keycloak-saml-core
CVE-2019-1010260 Vulnerability in maven package com.github.shyiko:ktlint
CVE-2022-28366 Vulnerability in maven package net.sourceforge.nekohtml:nekohtml
CVE-2022-23708 Vulnerability in maven package org.elasticsearch:elasticsearch