CRITICAL9.1
GHSA-86r9-39j9-99wp
Elliptic Curve Key Disclosure in go-jose
Quick fix
GHSA-86r9-39j9-99wp — gopkg.in/square/go-jose.v1: upgrade to the fixed version with the command below.
go get gopkg.in/square/go-jose.v1@v1.0.4Details
go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm. When deriving a shared key using ECDH-ES for an encrypted message, go-jose neglected to check that the received public key on a message is on the same curve as the static private key of the receiver, thus making it vulnerable to an invalid curve attack.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/gopkg.in/square/go-jose.v1
Introduced in:
0Fixed in: 1.0.4Fix
go get gopkg.in/square/go-jose.v1@v1.0.4Go/github.com/square/go-jose
Introduced in:
0Fixed in: 1.0.4Fix
go get github.com/square/go-jose@v1.0.4