Vulnerabilities/

Padding Oracle Attack due to Observable Timing Discrepancy in jose

Severity:
Medium

Description

jose is an npm library providing a number of cryptographic operations.

Recommendation

Update the jose package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
jose
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing