biscuit-auth
crates.io3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting biscuit-authpage 1 of 1
- CVE-2022-31053CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.0.02022-06-13
Biscuit is an authentication and authorization token for microservices architectures. The Biscuit specification version 1 contains a vulnerable algorithm that allows malicious actors to forge valid Γ-signatures. Such an attack would allow…
- CVE-2024-41949LOWCVSS 3.0EG 3.0✓ Fixed in 5.0.02024-08-01
biscuit-rust is the Rust implementation of Biscuit, an authentication and authorization token for microservices architectures. Third-party blocks can be generated without transferring the whole token to the third-party authority. Instead, …
- CVE-2024-42350LOWCVSS 3.0EG 3.0✓ Fixed in 5.0.02024-08-05
Biscuit is an authorization token with decentralized verification, offline attenuation and strong security policy enforcement based on a logic language. Third-party blocks can be generated without transferring the whole token to the third-…
Check whether biscuit-auth is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for biscuit-auth CVEs against the assets you own.
Start Free Scan →