Description
JPaseto before 0.3.0 generates weak hashes when using v2.local tokens.
Remediation
References
https://github.com/paseto-toolkit/jpaseto/releases/tag/jpaseto-0.3.0
Related Vulnerabilities
CVE-2018-1317 Vulnerability in maven package org.apache.zeppelin:zeppelin
CVE-2017-18352 Vulnerability in npm package rendertron-middleware
CVE-2021-38542 Vulnerability in maven package org.apache.james:james-server
CVE-2017-18640 Vulnerability in maven package org.yaml:snakeyaml
CVE-2017-12631 Vulnerability in maven package org.apache.cxf.fediz:fediz-spring3