CVE-2017-12972 | Nimbus JOSE+JWT up to 4.38 AAD data authenticity (ID 224 / WID-SEC-2022-0770)
A vulnerability marked as critical has been reported in Nimbus JOSE+JWT up to 4.38. This affects an unknown part of the component AAD Handler. This manipulation causes insufficient verification of data authenticity.
This vulnerability appears as CVE-2017-12972. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.