MEDIUM
GHSA-2c7c-3mj9-8fqh
Decryption of malicious PBES2 JWE objects can consume unbounded system resources
Quick fix
GHSA-2c7c-3mj9-8fqh — github.com/go-jose/go-jose/v3: upgrade to the fixed version with the command below.
go get github.com/go-jose/go-jose/v3@v3.0.1Details
The go-jose package is subject to a "billion hashes attack" causing denial-of-service when decrypting JWE inputs. This occurs when an attacker can provide a PBES2 encrypted JWE blob with a very large p2c value that, when decrypted, produces a denial-of-service.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/go-jose/go-jose/v3
Introduced in:
0Fixed in: 3.0.1Fix
go get github.com/go-jose/go-jose/v3@v3.0.1Go/github.com/square/go-jose
Introduced in:
0Fixed in: 2.6.2Fix
go get github.com/square/go-jose@v2.6.2