CVE-2017-12973
low
CVSS v3
3.1
CVSS v2
4.3
VIR risk
3.1
Description
Nimbus JOSE+JWT vulnerable to padding oracle attack
Predictions
Exploit likelihood
42%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/CHANGELOG.txt
Vendor advisory: cve@mitre.org — https://bitbucket.org/connect2id/nimbus-jose-jwt/commits/6a29f10f723f406eb25555f55842c59a43a38912
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | com.nimbusds:nimbus-jose-jwt | <4.39 | 4.39 |
Application impact
References
- https://bitbucket.org/connect2id/nimbus-jose-jwt/commits/6a29f10f723f406eb25555f55842c59a43a38912
- https://bitbucket.org/connect2id/nimbus-jose-jwt/issues/223/aescbc-return-immediately-on-invalid-hmac
- https://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/CHANGELOG.txt
- https://nvd.nist.gov/vuln/detail/CVE-2017-12973
CWEs
CWE-354
Verify integrity in audit chain (admin only). AS-IS.