Количество 4
Количество 4
CVE-2016-9121
go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm. When deriving a shared key using ECDH-ES for an encrypted message, go-jose neglected to check that the received public key on a message is on the same curve as the static private key of the receiver, thus making it vulnerable to an invalid curve attack.
CVE-2016-9121
go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm. When deriving a shared key using ECDH-ES for an encrypted message, go-jose neglected to check that the received public key on a message is on the same curve as the static private key of the receiver, thus making it vulnerable to an invalid curve attack.
CVE-2016-9121
go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH ...
GHSA-86r9-39j9-99wp
Elliptic Curve Key Disclosure in go-jose
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2016-9121 go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm. When deriving a shared key using ECDH-ES for an encrypted message, go-jose neglected to check that the received public key on a message is on the same curve as the static private key of the receiver, thus making it vulnerable to an invalid curve attack. | CVSS3: 9.1 | 1% Низкий | почти 9 лет назад | |
CVE-2016-9121 go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm. When deriving a shared key using ECDH-ES for an encrypted message, go-jose neglected to check that the received public key on a message is on the same curve as the static private key of the receiver, thus making it vulnerable to an invalid curve attack. | CVSS3: 9.1 | 1% Низкий | почти 9 лет назад | |
CVE-2016-9121 go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH ... | CVSS3: 9.1 | 1% Низкий | почти 9 лет назад | |
GHSA-86r9-39j9-99wp Elliptic Curve Key Disclosure in go-jose | CVSS3: 9.1 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу