Improper calculations in ECC implementation can trigger a Denial-of-Service (DoS)
- Severity:
- High
Description
When using the non-default “fallback” crypto back-end, ECC operations in node-jose can trigger a Denial-of-Service (DoS) condition, due to a possible infinite loop in an internal calculation. For some ECC operations, this condition is triggered randomly; for others, it can be triggered by malicious input.
Recommendation
Update the node-jose package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.2.0
- Patched version(s): 2.2.0
References
Related Issues
- Denial of Service (DoS) via the unsetByPath function in jsjoints - CVE-2020-28479
- Switcher Client contains Regular Expression Denial of Service (ReDoS) - CVE-2023-23925
- Zod denial of service vulnerability - CVE-2023-4316
- word-wrap vulnerable to Regular Expression Denial of Service - CVE-2023-26115
You might also like:
- Tags:
- npm
- node-jose
Anything's wrong? Let us know Last updated on February 16, 2023


