CVE-2017-16007

MEDIUM

Cisco Node-jose < 0.9.3 - Information Disclosure

Title source: rule
STIX 2.1

Description

node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and node.js-based servers. node-jose earlier than version 0.9.3 is vulnerable to an invalid curve attack. This allows an attacker to recover the private secret key when JWE with Key Agreement with Elliptic Curve Diffie-Hellman Ephemeral Static (ECDH-ES) is used.

References (4)

Core 4
Core References
Patch, Third Party Advisory x_refsource_misc
https://gist.github.com/asanso/fa25685348051ef6a28d49aa0f27a4ae
Third Party Advisory x_refsource_misc
https://nodesecurity.io/advisories/324

Scores

CVSS v3 5.9
EPSS 0.0025
EPSS Percentile 48.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (2)
cisco/node-jose < 0.9.3
npm/node-jose 0 - 0.9.3npm
Published Jun 04, 2018
Tracked Since Feb 18, 2026