Description
JPaseto before 0.3.0 generates weak hashes when using v2.local tokens.
Remediation
References
https://github.com/paseto-toolkit/jpaseto/releases/tag/jpaseto-0.3.0
Related Vulnerabilities
CVE-2022-25885 Vulnerability in npm package hummus
CVE-2020-7623 Vulnerability in npm package jscover
CVE-2021-22963 Vulnerability in npm package fastify-static
CVE-2022-29172 Vulnerability in maven package org.webjars.bower:auth0-lock
CVE-2021-39185 Vulnerability in maven package org.http4s:http4s-server