CVE-2024-28180

CVSS v3.1 4.3 (Medium)
43% Progress
EPSS 0.05 % (18th)
0.05% Progress
Advisories 36
NVD Status Awaiting Analysis

Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.

Weaknesses
CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)
CVE Status
PUBLISHED
NVD Status
Awaiting Analysis
CNA
GitHub, Inc.
Published Date
2024-03-09 01:15:07
(6 months ago)
Updated Date
2024-06-12 02:15:09
(3 months ago)
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...