Description
JPaseto before 0.3.0 generates weak hashes when using v2.local tokens.
Remediation
References
https://github.com/paseto-toolkit/jpaseto/releases/tag/jpaseto-0.3.0
Related Vulnerabilities
CVE-2019-1003095 Vulnerability in maven package org.jenkins-ci.plugins:perfectomobile
CVE-2023-36472 Vulnerability in npm package @strapi/plugin-content-manager
CVE-2018-20835 Vulnerability in maven package org.webjars.npm:tar-fs
CVE-2015-8862 Vulnerability in maven package org.webjars.npm:mustache
CVE-2013-4590 Vulnerability in maven package org.apache.tomcat:catalina