[GO-2024-2631] Decompression bomb vulnerability in github.com/go-jose/go-jose

Severity Medium
Affected Packages 3
Fixed Packages 3
CVEs 1
Source # ID Name URL
Security Advisory https://github.com/advisories/GHSA-c5q2-7r4c-mv6g
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:golang/gopkg.in/go-jose/go-jose.v2 gopkg.in/go-jose go-jose.v2 = 2.6.3
Affected pkg:golang/gopkg.in/go-jose/go-jose.v2 gopkg.in/go-jose go-jose.v2 >= 2.6.2 < 2.6.3
Fixed pkg:golang/github.com/go-jose/go-jose/v4 github.com/go-jose/go-jose v4 = 4.0.1
Affected pkg:golang/github.com/go-jose/go-jose/v4 github.com/go-jose/go-jose v4 >= 4.0.0 < 4.0.1
Fixed pkg:golang/github.com/go-jose/go-jose/v3 github.com/go-jose/go-jose v3 = 3.0.3
Affected pkg:golang/github.com/go-jose/go-jose/v3 github.com/go-jose/go-jose v3 >= 3.0.2 < 3.0.3
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...