Vulnerability Report: GO-2023-2409
- CVE-2023-50658, GHSA-mhpq-9638-x6pw, and 1 more
- Affects: github.com/dvsekhvalnov/jose2go
- Published: Dec 20, 2023
- Modified: Jul 02, 2024
An attacker controlled input of a PBES2 encrypted JWE blob can have a very large p2c value that, when decrypted, produces a denial-of-service.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.5.1-0.20231206184617-48ba0b76bc88
Aliases
References
- https://github.com/dvsekhvalnov/jose2go/issues/31
- https://www.blackhat.com/us-23/briefings/schedule/#three-new-attacks-against-json-web-tokens-31695
- https://github.com/dvsekhvalnov/jose2go/commit/a4584e9dd7128608fedbc67892eba9697f0d5317
- https://vuln.go.dev/ID/GO-2023-2409.json
Credits
- @mschwager
Feedback
See anything missing or incorrect?
Suggest an edit to this report.