Security News
MariaDB announced the general availability of MariaDB Community Server 10.6, a major new release that brings significant advancements to the open source MariaDB community. MariaDB Community Server 10.6 adds important features for developers with JSON table functionality, frees users from expensive proprietary ties with expanded PL/SQL compatibility and adds powerful insurance for bad database days with atomic DDL that supports MariaDB's multiple storage engine architecture.
JSON libraries using the JWE specification to create, sign and encrypt access tokens have been patched against an attack that allows for the recovery of a private key.
Critical vulnerabilities exist in several JSON Web Token (JWT) libraries – namely the JavaScript and PHP versions – that could let an attacker bypass the verification step.