目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2021-29443— jose 安全漏洞

CVSS 5.9 · Medium EPSS 1.17% · P64
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2021-29443 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Padding Oracle Attack due to Observable Timing Discrepancy in jose
来源: CVE Program / CVE List V5
Vulnerability Description
jose is an npm library providing a number of cryptographic operations. In vulnerable versions AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed `JWEDecryptionFailed` would be thrown. A possibly observable difference in timing when padding error would occur while decrypting the ciphertext makes a padding oracle and an adversary might be able to make use of that oracle to decrypt data without knowing the decryption key by issuing on average 128*b calls to the padding oracle (where b is the number of bytes in the ciphertext block). All major release versions have had a patch released which ensures the HMAC tag is verified before performing CBC decryption. The fixed versions are `^1.28.1 || ^2.0.5 || >=3.11.4`. Users should upgrade their v1.x dependency to ^1.28.1, their v2.x dependency to ^2.0.5, and their v3.x dependency to ^3.11.4. Thanks to Jason from Microsoft Vulnerability Research (MSVR) for bringing this up and Eva Sarafianou (@esarafianou) for helping to score this advisory.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
通过差异性导致的信息暴露
来源: CVE Program / CVE List V5
Vulnerability Title
jose 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
npm jose是美国npm公司的一个应用软件。使用本机加密运行时不依赖项的JWA,JWS,JWE,JWT,JWK。 jose 存在安全漏洞,该漏洞源于当填充oracle解密密文时,填充错误可能会发生。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
panvajose < 1.28.1 -

二、漏洞 CVE-2021-29443 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2021-29443 的情报信息

登录查看更多情报信息。

CVE-2021-29443 厂商安全公告 (1)

CVE-2021-29443 其他参考 (1)

同批安全公告 · panva · 2021-04-16 · 共 4 条

CVE-2021-294445.9 MEDIUMjose-browser-runtime 安全漏洞
CVE-2021-294455.9 MEDIUMjose-node-esm-runtime 安全漏洞
CVE-2021-294465.9 MEDIUMjose-node-cjs-runtime 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2021-29443

暂无评论


发表评论