Invalid Curve Attack in node-jose
Moderate severity
GitHub Reviewed
Published
Jul 20, 2018
to the GitHub Advisory Database
•
Updated Sep 6, 2023
Description
Published to the GitHub Advisory Database
Jul 20, 2018
Reviewed
Jun 16, 2020
Last updated
Sep 6, 2023
Affected versions of
node-jose
are vulnerable to an invalid curve attack. This allows an attacker to recover the private secret key when JWE with Key Agreement with Elliptic Curve Diffie-Hellman Ephemeral Static (ECDH-ES) is used.Proof of Concept
Recommendation
Update to version 0.9.3 or later.
References