Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-36083

Опубликовано: 07 сент. 2022
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

JOSE is "JSON Web Almost Everything" - JWA, JWS, JWE, JWT, JWK, JWKS with no dependencies using runtime's native crypto in Node.js, Browser, Cloudflare Workers, Electron, and Deno. The PBKDF2-based JWE key management algorithms expect a JOSE Header Parameter named p2c PBES2 Count, which determines how many PBKDF2 iterations must be executed in order to derive a CEK wrapping key. The purpose of this parameter is to intentionally slow down the key derivation function in order to make password brute-force and dictionary attacks more expensive. This makes the PBES2 algorithms unsuitable for situations where the JWE is coming from an untrusted source: an adversary can intentionally pick an extremely high PBES2 Count value, that will initiate a CPU-bound computation that may take an unreasonable amount of time to finish. Under certain conditions, it is possible to have the user's environment consume unreasonable amount of CPU time. The impact is limited only to users utilizing the JWE decr

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:jose_project:jose:*:*:*:*:*:node.js:*:*
Версия от 1.0.0 (включая) до 1.28.2 (исключая)
cpe:2.3:a:jose_project:jose:*:*:*:*:*:node.js:*:*
Версия от 2.0.0 (включая) до 2.0.6 (исключая)
cpe:2.3:a:jose_project:jose:*:*:*:*:*:node.js:*:*
Версия от 3.0.0 (включая) до 3.20.4 (исключая)
cpe:2.3:a:jose_project:jose:*:*:*:*:*:node.js:*:*
Версия от 4.0.0 (включая) до 4.9.2 (исключая)

EPSS

Процентиль: 59%
0.00386
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400
CWE-834

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 3 лет назад

JOSE is "JSON Web Almost Everything" - JWA, JWS, JWE, JWT, JWK, JWKS with no dependencies using runtime's native crypto in Node.js, Browser, Cloudflare Workers, Electron, and Deno. The PBKDF2-based JWE key management algorithms expect a JOSE Header Parameter named `p2c` PBES2 Count, which determines how many PBKDF2 iterations must be executed in order to derive a CEK wrapping key. The purpose of this parameter is to intentionally slow down the key derivation function in order to make password brute-force and dictionary attacks more expensive. This makes the PBES2 algorithms unsuitable for situations where the JWE is coming from an untrusted source: an adversary can intentionally pick an extremely high PBES2 Count value, that will initiate a CPU-bound computation that may take an unreasonable amount of time to finish. Under certain conditions, it is possible to have the user's environment consume unreasonable amount of CPU time. The impact is limited only to users utilizing the JWE d...

CVSS3: 5.3
debian
больше 3 лет назад

JOSE is "JSON Web Almost Everything" - JWA, JWS, JWE, JWT, JWK, JWKS w ...

CVSS3: 5.3
github
больше 3 лет назад

JOSE vulnerable to resource exhaustion via specifically crafted JWE

EPSS

Процентиль: 59%
0.00386
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400
CWE-834