Описание
JWX is Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. This vulnerability allows an attacker with a trusted public key to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. This issue has been patched in versions 1.2.29 and 2.0.21.
Ссылки
- ProductRelease Notes
- ProductRelease Notes
- ExploitVendor Advisory
- ProductRelease Notes
- ProductRelease Notes
- ExploitVendor Advisory
Уязвимые конфигурации
Одно из
EPSS
6.8 Medium
CVSS3
Дефекты
Связанные уязвимости
JWX is Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. This vulnerability allows an attacker with a trusted public key to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. This issue has been patched in versions 1.2.29 and 2.0.21.
JWX vulnerable to a denial of service attack using compressed JWE message
Уязвимость библиотеки jwx языка программирования Go, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
6.8 Medium
CVSS3