Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46664
HistoryApr 29, 2024 - 6:33 a.m.

Improper Signature Validation

2024-04-2906:33:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21
vulnerability
improper verification
openssh ecdsa keys
security measures
cryptographic functions
crafted signatures
algorithm parameter

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

AI Score

6.8

Confidence

High

EPSS

0

Percentile

9.0%

python-jose is vulnerable to Improper Signature Validation. This vulnerability is due to improper verification of OpenSSH ECDSA keys along with other key formats, allowing attackers to bypass security measures or manipulate cryptographic functions by submitting crafted signatures with a specific signature algorithm header. To mitigate the vulnerability, ensure the algorithm parameter is set when calling the decode() function.

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

AI Score

6.8

Confidence

High

EPSS

0

Percentile

9.0%