Biscuit-Auth Biscuit vulnerabilities
2 known vulnerabilities affecting biscuit-auth/biscuit.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1LOW1
Vulnerabilities
Page 1 of 1
CVE-2024-42350LOWCVSS 3.0fixed in 42024-08-05
CVE-2024-42350 [LOW] CWE-668 CVE-2024-42350: Biscuit is an authorization token with decentralized verification, offline attenuation and strong se
Biscuit is an authorization token with decentralized verification, offline attenuation and strong security policy enforcement based on a logic language. Third-party blocks can be generated without transferring the whole token to the third-party authority. Instead, a `ThirdPartyBlock` request can be sent, providing only the necessary info to generate a
nvd
CVE-2022-31053CRITICALCVSS 9.8vbiscuit-auth >= 1.0.0, < 2.0.0vbiscuit-haskell = 0.1.1.0+2 more2022-06-13
CVE-2022-31053 [CRITICAL] CWE-347 CVE-2022-31053: Biscuit is an authentication and authorization token for microservices architectures. The Biscuit sp
Biscuit is an authentication and authorization token for microservices architectures. The Biscuit specification version 1 contains a vulnerable algorithm that allows malicious actors to forge valid Γ-signatures. Such an attack would allow an attacker to create a token with any access level. The version 2 of the specification mandates a different a
nvd