Description
JPaseto before 0.3.0 generates weak hashes when using v2.local tokens.
Remediation
References
https://github.com/paseto-toolkit/jpaseto/releases/tag/jpaseto-0.3.0
Related Vulnerabilities
CVE-2022-25926 Vulnerability in npm package window-control
CVE-2022-4493 Vulnerability in maven package io.scif:scifio
CVE-2015-7501 Vulnerability in maven package org.apache.commons:commons-collections4
CVE-2014-7810 Vulnerability in maven package org.apache.tomcat:jasper
CVE-2021-43306 Vulnerability in maven package org.webjars.npm:jquery-validation