Insecure encryption algorithm In gree/jose

Description

PHP JOSE Library by Gree Inc. Uses a Broken or Risky Cryptographic Algorithm The PHP JOSE Library by Gree Inc. prior to 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions