Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-45767

Опубликовано: 01 авг. 2025
Источник: redhat
CVSS3: 5.6

Описание

jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do not meet recommended security standards" does not reflect guidance in a final publication.

A flaw was found in Jose, where the library uses a weak encryption algorithm, allowing an attacker to decrypt sensitive data. A network-based attacker can exploit this vulnerability without authentication. Successful exploitation results in the exposure of confidential information, potentially leading to a significant impact on data confidentiality. This weakness occurs from the use of an insecure cryptographic construction.

Отчет

The severity of this vulnerability is rated Moderate, as it does not impact system availability. The effects are confined to the application layer, without compromising the underlying system stability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat/cryostat-openshift-console-plugin-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel8Affected
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Affected
OpenShift Serverlessopenshift-serverless-1/kn-backstage-plugins-eventmesh-rhel8Will not fix
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel9Affected
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Affected
Red Hat Developer Hubrhdh/rhdh-rhel9-operatorNot affected
Red Hat Enterprise Linux 10joseNot affected
Red Hat Enterprise Linux 7joseNot affected
Red Hat Enterprise Linux 8joseNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-327
https://bugzilla.redhat.com/show_bug.cgi?id=2385958jose: Jose Weak Encryption Vulnerability

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
21 день назад

jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do not meet recommended security standards" does not reflect guidance in a final publication.

CVSS3: 7
nvd
21 день назад

jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do not meet recommended security standards" does not reflect guidance in a final publication.

CVSS3: 7
debian
21 день назад

jose v6.0.10 was discovered to contain weak encryption. NOTE: this is ...

CVSS3: 7
github
21 день назад

jose v6.0.10 was discovered to contain weak encryption.

5.6 Medium

CVSS3