Vulnerabilities > Connect2Id > Nimbus Jose JWT > Low
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-08-20 | CVE-2017-12973 | Improper Validation of Integrity Check Value vulnerability in Connect2Id Nimbus Jose+Jwt Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackers to conduct a padding oracle attack. | 3.1 |