VDB
Sign up
MEDIUM5.9

GHSA-rvj9-8cvx-3vq9

Invalid Curve Attack in node-jose

Quick fix

GHSA-rvj9-8cvx-3vq9 — node-jose: upgrade to the fixed version with the command below.

npm install node-jose@0.9.3

Details

Affected versions of `node-jose` are vulnerable to an invalid curve attack. This allows an attacker to recover the private secret key when JWE with Key Agreement with Elliptic Curve Diffie-Hellman Ephemeral Static (ECDH-ES) is used.

[Proof of Concept](https://gist.github.com/asanso/fa25685348051ef6a28d49aa0f27a4ae)

## Recommendation

Update to version 0.9.3 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/node-jose
Introduced in: 0Fixed in: 0.9.3
Fixnpm install node-jose@0.9.3

References