[GO-2024-2631] Decompression bomb vulnerability in github.com/go-jose/go-jose
Severity
Medium
Affected Packages
3
Fixed Packages
3
CVEs
1
An attacker could send a JWE containing compressed data that used large amounts
of memory and CPU when decompressed by Decrypt or DecryptMulti.
Package | Affected Version |
---|---|
pkg:golang/gopkg.in/go-jose/go-jose.v2 | >= 2.6.2, < 2.6.3 |
pkg:golang/github.com/go-jose/go-jose/v4 | >= 4.0.0, < 4.0.1 |
pkg:golang/github.com/go-jose/go-jose/v3 | >= 3.0.2, < 3.0.3 |
Package | Fixed Version |
---|---|
pkg:golang/gopkg.in/go-jose/go-jose.v2 | = 2.6.3 |
pkg:golang/github.com/go-jose/go-jose/v4 | = 4.0.1 |
pkg:golang/github.com/go-jose/go-jose/v3 | = 3.0.3 |
- ID
- GO-2024-2631
- Severity
- medium
- Severity from
- CVE-2024-28180
- URL
- https://pkg.go.dev/vuln/GO-2024-2631
- Published
-
2024-03-11T19:00:25
(6 months ago) - Modified
-
2024-05-14T19:19:00
(4 months ago) - Other Advisories
-
- ALAS2-2024-2618
- ALPINE:CVE-2024-28180
- ALSA-2024:2549
- ALSA-2024:3254
- ALSA-2024:3826
- ALSA-2024:3827
- ALSA-2024:3968
- ELSA-2024-2549
- ELSA-2024-3254
- ELSA-2024-3826
- ELSA-2024-3827
- ELSA-2024-3968
- FEDORA-2024-22f1e313dd
- FEDORA-2024-453ee0b3b9
- FEDORA-2024-45f0a1df95
- FEDORA-2024-529fe8a802
- FEDORA-2024-560a7aca85
- FEDORA-2024-831bad8f8f
- FEDORA-2024-9231308a4f
- FEDORA-2024-a8a4ce2864
- FEDORA-2024-c95d3199c5
- RHSA-2024:2549
- RHSA-2024:3254
- RHSA-2024:3826
- RHSA-2024:3827
- RHSA-2024:3968
- RLSA-2024:2549
- RLSA-2024:3826
- RLSA-2024:3827
- SUSE-SU-2024:1987-1
- SUSE-SU-2024:1987-2
- SUSE-SU-2024:2754-1
- SUSE-SU-2024:3120-1
- SUSE-SU-2024:3151-1
- SUSE-SU-2024:3186-1
Source | # ID | Name | URL |
---|---|---|---|
Security Advisory | https://github.com/advisories/GHSA-c5q2-7r4c-mv6g |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Fixed | pkg:golang/gopkg.in/go-jose/go-jose.v2 | gopkg.in/go-jose | go-jose.v2 | = 2.6.3 | |||
Affected | pkg:golang/gopkg.in/go-jose/go-jose.v2 | gopkg.in/go-jose | go-jose.v2 | >= 2.6.2 < 2.6.3 | |||
Fixed | pkg:golang/github.com/go-jose/go-jose/v4 | github.com/go-jose/go-jose | v4 | = 4.0.1 | |||
Affected | pkg:golang/github.com/go-jose/go-jose/v4 | github.com/go-jose/go-jose | v4 | >= 4.0.0 < 4.0.1 | |||
Fixed | pkg:golang/github.com/go-jose/go-jose/v3 | github.com/go-jose/go-jose | v3 | = 3.0.3 | |||
Affected | pkg:golang/github.com/go-jose/go-jose/v3 | github.com/go-jose/go-jose | v3 | >= 3.0.2 < 3.0.3 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |