Panva Jose vulnerabilities
4 known vulnerabilities affecting panva/jose.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2024-28176MEDIUMCVSS 5.9v>= 3.0.0, <= 4.15.4fixed in 2.0.72024-03-09
CVE-2024-28176 [MEDIUM] CWE-400 CVE-2024-28176: jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tok
jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has
been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for
cvelistv5nvd
CVE-2022-36083MEDIUMCVSS 5.3v>= 1.0, < 1.28.2v>= 2.0, < 2.0.6+2 more2022-09-07
CVE-2022-36083 [MEDIUM] CWE-400 CVE-2022-36083: JOSE is "JSON Web Almost Everything" - JWA, JWS, JWE, JWT, JWK, JWKS with no dependencies using runt
JOSE is "JSON Web Almost Everything" - JWA, JWS, JWE, JWT, JWK, JWKS with no dependencies using runtime's native crypto in Node.js, Browser, Cloudflare Workers, Electron, and Deno. The PBKDF2-based JWE key management algorithms expect a JOSE Header Parameter named `p2c` PBES2 Count, which determines how many PBKDF2 iterations must be executed in ord
cvelistv5nvd
CVE-2021-29443MEDIUMCVSS 5.9fixed in 1.28.1v>= 2.0.0, < 2.0.5+1 more2021-04-16
CVE-2021-29443 [MEDIUM] CWE-203 CVE-2021-29443: jose is an npm library providing a number of cryptographic operations. In vulnerable versions AES_CB
jose is an npm library providing a number of cryptographic operations. In vulnerable versions AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed `JWEDecryptionFailed` would be thrown. A possibly observable difference in timing when
cvelistv5nvd
CVE-2021-29444MEDIUMCVSS 5.9fixed in 3.11.42021-04-16
CVE-2021-29444 [MEDIUM] CWE-203 CVE-2021-29444: jose-browser-runtime is an npm package which provides a number of cryptographic functions. In versio
jose-browser-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed `JWEDecryptionFailed` would be thrown. But a possibly obse
cvelistv5nvd