CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AI Score
Confidence
Low
Jose is a C-language implementation of the Javascript Object Signing and Encryption standards. The jose package is a dependency of the clevis and tang packages, together providing Network Bound Disk Encryption (NBDE) in AlmaLinux.
Security Fix(es):
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
almalinux | 8 | i686 | libjose | < 10-2.el8_10.3 | libjose-10-2.el8_10.3.i686.rpm |
almalinux | 8 | i686 | libjose-devel | < 10-2.el8_10.3 | libjose-devel-10-2.el8_10.3.i686.rpm |
almalinux | 8 | x86_64 | libjose | < 10-2.el8_10.3 | libjose-10-2.el8_10.3.x86_64.rpm |
almalinux | 8 | x86_64 | libjose-devel | < 10-2.el8_10.3 | libjose-devel-10-2.el8_10.3.x86_64.rpm |
almalinux | 8 | x86_64 | jose | < 10-2.el8_10.3 | jose-10-2.el8_10.3.x86_64.rpm |
almalinux | 8 | aarch64 | libjose-devel | < 10-2.el8_10.3 | libjose-devel-10-2.el8_10.3.aarch64.rpm |
almalinux | 8 | aarch64 | libjose | < 10-2.el8_10.3 | libjose-10-2.el8_10.3.aarch64.rpm |
almalinux | 8 | aarch64 | jose | < 10-2.el8_10.3 | jose-10-2.el8_10.3.aarch64.rpm |
almalinux | 8 | ppc64le | libjose | < 10-2.el8_10.3 | libjose-10-2.el8_10.3.ppc64le.rpm |
almalinux | 8 | ppc64le | jose | < 10-2.el8_10.3 | jose-10-2.el8_10.3.ppc64le.rpm |