Vulnerabilities/

Invalid Curve Attack in node-jose

Severity:
Medium

Description

Affected versions of node-jose are vulnerable to an invalid curve attack. This allows an attacker to recover the private secret key when JWE with Key Agreement with Elliptic Curve Diffie-Hellman Ephemeral Static (ECDH-ES) is used.

Proof of Concept

Recommendation

Update the node-jose package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
node-jose
Anything's wrong? Let us know Last updated on September 06, 2023

This issue is available in SmartScanner Professional

See Pricing