WS-2023-0116 (Medium) detected in jose4j-0.7.9.jar - autoclosed #2943
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
Milestone
WS-2023-0116 - Medium Severity Vulnerability
Vulnerable Library - jose4j-0.7.9.jar
The jose.4.j library is a robust and easy to use open source implementation of JSON Web Token (JWT) and the JOSE specification suite (JWS, JWE, and JWK). It is written in Java and relies solely on the JCA APIs for cryptography. Please see https://bitbucket.org/b_c/jose4j/wiki/Home for more info, examples, etc..
Library home page: https://bitbucket.org/b_c/jose4j/
Path to dependency file: /data-prepper-main/build.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.bitbucket.b_c/jose4j/0.7.9/b44a2235728ab1cad9ffd06013500f09a5f1d241/jose4j-0.7.9.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.bitbucket.b_c/jose4j/0.7.9/b44a2235728ab1cad9ffd06013500f09a5f1d241/jose4j-0.7.9.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.bitbucket.b_c/jose4j/0.7.9/b44a2235728ab1cad9ffd06013500f09a5f1d241/jose4j-0.7.9.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.bitbucket.b_c/jose4j/0.7.9/b44a2235728ab1cad9ffd06013500f09a5f1d241/jose4j-0.7.9.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.bitbucket.b_c/jose4j/0.7.9/b44a2235728ab1cad9ffd06013500f09a5f1d241/jose4j-0.7.9.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.bitbucket.b_c/jose4j/0.7.9/b44a2235728ab1cad9ffd06013500f09a5f1d241/jose4j-0.7.9.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.bitbucket.b_c/jose4j/0.7.9/b44a2235728ab1cad9ffd06013500f09a5f1d241/jose4j-0.7.9.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.bitbucket.b_c/jose4j/0.7.9/b44a2235728ab1cad9ffd06013500f09a5f1d241/jose4j-0.7.9.jar
Dependency Hierarchy:
Found in HEAD commit: 8bb96ddcf23859e0e7b55c3a9add5d77eddbccb0
Found in base branch: main
Vulnerability Details
RSA1_5 in jose4j is susceptible to chosen ciphertext attacks. The
attack allows to decrypt RSA1_5 or RSA_OAEP encrypted ciphertexts. It may be feasible to sign with affected keys.
Publish Date: 2023-04-27
URL: WS-2023-0116
CVSS 3 Score Details (5.3)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-jgvc-jfgh-rjvv
Release Date: 2023-04-27
Fix Resolution: org.bitbucket.b_c:jose4j:0.9.3
The text was updated successfully, but these errors were encountered: