VDB
Sign up
CRITICAL9.1

GHSA-86r9-39j9-99wp

Elliptic Curve Key Disclosure in go-jose

Quick fix

GHSA-86r9-39j9-99wp — gopkg.in/square/go-jose.v1: upgrade to the fixed version with the command below.

go get gopkg.in/square/go-jose.v1@v1.0.4

Details

go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm. When deriving a shared key using ECDH-ES for an encrypted message, go-jose neglected to check that the received public key on a message is on the same curve as the static private key of the receiver, thus making it vulnerable to an invalid curve attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/gopkg.in/square/go-jose.v1
Introduced in: 0Fixed in: 1.0.4
Fixgo get gopkg.in/square/go-jose.v1@v1.0.4
Go/github.com/square/go-jose
Introduced in: 0Fixed in: 1.0.4
Fixgo get github.com/square/go-jose@v1.0.4

References