Uploaded image for project: 'Kafka'
  1. Kafka
  2. KAFKA-14994

jose4j is vulnerable to CVE- Improper Cryptographic Algorithm

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 3.4.0
    • 3.5.0, 3.4.1
    • None
    • Patch, Important

    Description

      Jose4j has the following vulnerability with high score of 7.1.
      jose4j is vulnerable to Improper Cryptographic Algorithm. The vulnerability exists due to the way `RSA1_5` and `RSA_OAEP` is implemented, allowing an attacker to decrypt `RSA1_5` or `RSA_OAEP` encrypted ciphertexts, and in addition, it may be feasible to sign with affected keys.

      Please help upgrade the library to latest version
      Current version in use: 0.7.9
      Latest version with the fix: 0.9.3
      CVE-

      Attachments

        Activity

          People

            atusharm Atul Sharma
            jetlyg Gaurav Jetly
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: