Vulnerability library
Security checkJuly 21, 2023

JOSE vulnerable to resource exhaustion via specifically crafted JWE - jose-node-cjs-runtime

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

The PBKDF2-based JWE key management algorithms expect a JOSE Header Parameter named p2c (PBES2 Count), which determines how many PBKDF2 iterations must be executed in order to derive a CEK wrapping key.

Recommendation

Update the jose-node-cjs-runtime package to the latest compatible version. Followings are version details:

  • Affected version(s): **>= 4.0.0, <= 4.9.1 >= 3.0.0, <= 3.20.3**
  • Patched version(s): **4.9.2 3.20.4**

References

Could your website be exposed too?

SmartScanner can check your website for JOSE vulnerable to resource exhaustion via specifically crafted JWE - jose-node-cjs-runtime and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated July 21, 2023