Vulnerabilities/

Improper calculations in ECC implementation can trigger a Denial-of-Service (DoS)

Severity:
High

Description

When using the non-default “fallback” crypto back-end, ECC operations in node-jose can trigger a Denial-of-Service (DoS) condition, due to a possible infinite loop in an internal calculation. For some ECC operations, this condition is triggered randomly; for others, it can be triggered by malicious input.

Recommendation

Update the node-jose package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
node-jose
Anything's wrong? Let us know Last updated on February 16, 2023

This issue is available in SmartScanner Professional

See Pricing