Biscuitsec Biscuit-Auth vulnerabilities
2 known vulnerabilities affecting biscuitsec/biscuit-auth.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2024-41949MEDIUMCVSS 6.4fixed in 5.0.02024-08-01
CVE-2024-41949 [MEDIUM] CWE-269 CVE-2024-41949: biscuit-rust is the Rust implementation of Biscuit, an authentication and authorization token for mi
biscuit-rust is the Rust implementation of Biscuit, an authentication and authorization token for microservices architectures. Third-party blocks can be generated without transferring the whole token to the third-party authority. Instead, a ThirdPartyBlock request can be sent, providing only the necessary info to generate a third-party block and to
ghsanvdosv
CVE-2022-31053CRITICALCVSS 9.8≥ 1.0.0, ≤ 1.1.02022-06-13
CVE-2022-31053 [CRITICAL] CWE-347 CVE-2022-31053: Biscuit is an authentication and authorization token for microservices architectures. The Biscuit sp
Biscuit is an authentication and authorization token for microservices architectures. The Biscuit specification version 1 contains a vulnerable algorithm that allows malicious actors to forge valid Γ-signatures. Such an attack would allow an attacker to create a token with any access level. The version 2 of the specification mandates a different a
ghsanvdosv