CVE-2017-12972
high
CVSS v3
7.5
CVSS v2
5.0
VIR risk
7.5
Description
Nimbus JOSE+JWT missing overflow check
Predictions
Exploit likelihood
83%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/CHANGELOG.txt
Vendor advisory: cve@mitre.org — https://bitbucket.org/connect2id/nimbus-jose-jwt/issues/224/byte-to-bit-overflow-in-cbc
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | com.nimbusds:nimbus-jose-jwt | <4.39 | 4.39 |
Application impact
References
- https://bitbucket.org/connect2id/nimbus-jose-jwt/commits/0d2bd649ea386539220d4facfe1f65eb1dadb86c
- https://bitbucket.org/connect2id/nimbus-jose-jwt/issues/224/byte-to-bit-overflow-in-cbc
- https://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/CHANGELOG.txt
- https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2017-12972
- https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E
CWEs
CWE-345
Verify integrity in audit chain (admin only). AS-IS.