ZeroHour

CVE-2017-12974

CVSS 3.0
7.5 high
EPSS
1%p68
Published
()
Modified
Description

Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve, which allows attackers to conduct an Invalid Curve Attack in environments where the JCE provider lacks the applicable curve validation.

Vendors
connect2id
Products
nimbus jose\+jwt
Weakness
CWE-347
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.