lexik/jwt-authentication-bundle Security Advisories for v2.9.0 (2)
-
[LOW] User enumeration in authentication mechanisms
PKSA-9jqh-7vg4-s5nf GHSA-2frx-j9hj-6c65
Affected version: >=2.11.0,<2.11.3|<2.10.7
Reported by:
GitHub -
[MEDIUM] CVE-2021-21424: Prevent user enumeration via response content in authentication mechanisms
PKSA-kmhm-75ht-w8tg CVE-2021-21424 GHSA-5pv8-ppvj-4h68
Affected version: >=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.8.0|>=2.8.0,<2.9.0|>=2.9.0,<2.10.0|>=2.10.0,<2.10.7|>=2.11.0,<2.11.3
Reported by:
GitHub, FriendsOfPHP/security-advisories