CVE-2017-12973
published 2017-08-20CVE-2017-12973: Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackers to conduct a…
PriorityP48low3.1CVSS 3.0
AVNACHPRNUIRSUCLINAN
EPSS
0.64%
46.3th percentile
Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackers to conduct a padding oracle attack.
Affected
129 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
| connect2id | nimbus_jose_+jwt | — | — |
CVSS provenance
nvdv3.03.1LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Nimbus JOSE+JWT vulnerable to padding oracle attack
ghsa·2022-05-13
CVE-2017-12973 [LOW] CWE-354 Nimbus JOSE+JWT vulnerable to padding oracle attack
Nimbus JOSE+JWT vulnerable to padding oracle attack
Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackers to conduct a padding oracle attack.
OSV
Nimbus JOSE+JWT vulnerable to padding oracle attack
osv·2022-05-13
CVE-2017-12973 [LOW] Nimbus JOSE+JWT vulnerable to padding oracle attack
Nimbus JOSE+JWT vulnerable to padding oracle attack
Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackers to conduct a padding oracle attack.
OSV
openjpeg2 vulnerabilities
osv·2021-03-17·CVSS 6.5
CVE-2016-10506 openjpeg2 vulnerabilities
openjpeg2 vulnerabilities
It was discovered that OpenJPEG incorrectly handled certain image files. A
remote attacker could possibly use this issue to cause a denial of service.
CVE-2016-10506 and CVE-2017-12982 affected only Ubuntu 16.04 ESM.
CVE-2018-16375, CVE-2018-20845 and CVE-2019-12973 affected only
Ubuntu 18.04 ESM.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bitbucket.org/connect2id/nimbus-jose-jwt/commits/6a29f10f723f406eb25555f55842c59a43a38912https://bitbucket.org/connect2id/nimbus-jose-jwt/issues/223/aescbc-return-immediately-on-invalid-hmachttps://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/CHANGELOG.txthttps://bitbucket.org/connect2id/nimbus-jose-jwt/commits/6a29f10f723f406eb25555f55842c59a43a38912https://bitbucket.org/connect2id/nimbus-jose-jwt/issues/223/aescbc-return-immediately-on-invalid-hmachttps://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/CHANGELOG.txt
2017-08-20
Published