Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 74

Количество 74

rocky логотип

RLSA-2024:3827

около 2 лет назад

Moderate: buildah security and bug fix update

EPSS: Низкий
rocky логотип

RLSA-2024:3826

около 2 лет назад

Moderate: podman security and bug fix update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3827

около 2 лет назад

ELSA-2024-3827: buildah security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3826

около 2 лет назад

ELSA-2024-3826: podman security and bug fix update (MODERATE)

EPSS: Низкий
rocky логотип

RLSA-2024:3968

почти 2 года назад

Moderate: container-tools:rhel8 bug fix and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3968

около 2 лет назад

ELSA-2024-3968: container-tools:ol8 bug fix and enhancement update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2024-28176

больше 2 лет назад

jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. Under certain conditions it is possible to have the user's environment consume unreasonable amount of CPU time or memory during JWE Decryption operations. This issue has been patched in versions 2.0.7 and 4.15.5.

CVSS3: 4.9
EPSS: Низкий
redhat логотип

CVE-2024-28176

больше 2 лет назад

jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. Under certain conditions it is possible to have the user's environment consume unreasonable amount of CPU time or memory during JWE Decryption operations. This issue has been patched in versions 2.0.7 and 4.15.5.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-28176

больше 2 лет назад

jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. Under certain conditions it is possible to have the user's environment consume unreasonable amount of CPU time or memory during JWE Decryption operations. This issue has been patched in versions 2.0.7 and 4.15.5.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-hhhv-q57g-882q

больше 2 лет назад

jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintext

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2024-01954

больше 2 лет назад

Уязвимость модуля JavaScript для подписи и шифрования объектов JSON jose, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 4.9
EPSS: Низкий
rocky логотип

RLSA-2024:9181

больше 1 года назад

Moderate: jose security update

EPSS: Низкий
rocky логотип

RLSA-2024:5294

около 1 года назад

Moderate: jose security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-9181

больше 1 года назад

ELSA-2024-9181: jose security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-5294

почти 2 года назад

ELSA-2024-5294: jose security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2024-28180

больше 2 лет назад

Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2024-28180

больше 2 лет назад

Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-28180

больше 2 лет назад

Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2024-28180

больше 1 года назад

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-28180

больше 2 лет назад

Package jose aims to provide an implementation of the Javascript Objec ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2024:3827

Moderate: buildah security and bug fix update

около 2 лет назад
rocky логотип
RLSA-2024:3826

Moderate: podman security and bug fix update

около 2 лет назад
oracle-oval логотип
ELSA-2024-3827

ELSA-2024-3827: buildah security and bug fix update (MODERATE)

около 2 лет назад
oracle-oval логотип
ELSA-2024-3826

ELSA-2024-3826: podman security and bug fix update (MODERATE)

около 2 лет назад
rocky логотип
RLSA-2024:3968

Moderate: container-tools:rhel8 bug fix and enhancement update

почти 2 года назад
oracle-oval логотип
ELSA-2024-3968

ELSA-2024-3968: container-tools:ol8 bug fix and enhancement update (MODERATE)

около 2 лет назад
ubuntu логотип
CVE-2024-28176

jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. Under certain conditions it is possible to have the user's environment consume unreasonable amount of CPU time or memory during JWE Decryption operations. This issue has been patched in versions 2.0.7 and 4.15.5.

CVSS3: 4.9
2%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-28176

jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. Under certain conditions it is possible to have the user's environment consume unreasonable amount of CPU time or memory during JWE Decryption operations. This issue has been patched in versions 2.0.7 and 4.15.5.

CVSS3: 5.3
2%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-28176

jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. Under certain conditions it is possible to have the user's environment consume unreasonable amount of CPU time or memory during JWE Decryption operations. This issue has been patched in versions 2.0.7 and 4.15.5.

CVSS3: 4.9
2%
Низкий
больше 2 лет назад
github логотип
GHSA-hhhv-q57g-882q

jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintext

CVSS3: 5.3
2%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-01954

Уязвимость модуля JavaScript для подписи и шифрования объектов JSON jose, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 4.9
2%
Низкий
больше 2 лет назад
rocky логотип
RLSA-2024:9181

Moderate: jose security update

больше 1 года назад
rocky логотип
RLSA-2024:5294

Moderate: jose security update

около 1 года назад
oracle-oval логотип
ELSA-2024-9181

ELSA-2024-9181: jose security update (MODERATE)

больше 1 года назад
oracle-oval логотип
ELSA-2024-5294

ELSA-2024-5294: jose security update (MODERATE)

почти 2 года назад
ubuntu логотип
CVE-2024-28180

Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.

CVSS3: 4.3
2%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-28180

Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.

CVSS3: 4.3
2%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-28180

Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.

CVSS3: 4.3
2%
Низкий
больше 2 лет назад
msrc логотип
CVSS3: 4.3
2%
Низкий
больше 1 года назад
debian логотип
CVE-2024-28180

Package jose aims to provide an implementation of the Javascript Objec ...

CVSS3: 4.3
2%
Низкий
больше 2 лет назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.