Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:41361
HistoryJul 19, 2023 - 9:31 a.m.

Weak Encryption

2023-07-1909:31:48
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
vulnerability
libcjose.so
weak encryption
jwe.c
authentication tag
unauthorized access
software

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

EPSS

0.003

Percentile

65.9%

libcjose.so is vulnerable to weak encryption. The vulnerability exists in jwe.c because it does not properly validate the authentication tag according to the spec, which may allow an attacker to access unauthorized information in the system by modifying the JWE.

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

EPSS

0.003

Percentile

65.9%