VDB
Sign up
MEDIUM

GHSA-2c7c-3mj9-8fqh

Decryption of malicious PBES2 JWE objects can consume unbounded system resources

Quick fix

GHSA-2c7c-3mj9-8fqh — github.com/go-jose/go-jose/v3: upgrade to the fixed version with the command below.

go get github.com/go-jose/go-jose/v3@v3.0.1

Details

The go-jose package is subject to a "billion hashes attack" causing denial-of-service when decrypting JWE inputs. This occurs when an attacker can provide a PBES2 encrypted JWE blob with a very large p2c value that, when decrypted, produces a denial-of-service.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/go-jose/go-jose/v3
Introduced in: 0Fixed in: 3.0.1
Fixgo get github.com/go-jose/go-jose/v3@v3.0.1
Go/github.com/square/go-jose
Introduced in: 0Fixed in: 2.6.2
Fixgo get github.com/square/go-jose@v2.6.2

References