CVE-2017-12973

LOW

Nimbus JOSE+JWT <4.39 - Info Disclosure

Title source: llm
STIX 2.1

Description

Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackers to conduct a padding oracle attack.

Scores

CVSS v3 3.1
EPSS 0.0023
EPSS Percentile 45.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

Details

CWE
CWE-354
Status published
Products (50)
com.nimbusds/nimbus-jose-jwt 0 - 4.39Maven
connect2id/nimbus_jose\+jwt 1.0
connect2id/nimbus_jose\+jwt 1.1
connect2id/nimbus_jose\+jwt 1.2
connect2id/nimbus_jose\+jwt 1.3
connect2id/nimbus_jose\+jwt 1.4
connect2id/nimbus_jose\+jwt 1.5
connect2id/nimbus_jose\+jwt 1.6
connect2id/nimbus_jose\+jwt 1.7
connect2id/nimbus_jose\+jwt 1.8
... and 40 more
Published Aug 20, 2017
Tracked Since Feb 18, 2026