CVE-2017-12973

low
Published 2017-08-20 · Modified 2023-11-08
CVSS v3
3.1
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
CVSS v2
4.3
VIR risk
3.1

Description

Nimbus JOSE+JWT vulnerable to padding oracle attack

Predictions

Exploit likelihood
42%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/CHANGELOG.txt

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://bitbucket.org/connect2id/nimbus-jose-jwt/commits/6a29f10f723f406eb25555f55842c59a43a38912

Package impact

EcosystemPackageVulnerableFixed
java Mavencom.nimbusds:nimbus-jose-jwt<4.394.39

Application impact

VendorProductVersionsFixed
connect2idnimbus_jose\+jwt1.0
connect2idnimbus_jose\+jwt1.1
connect2idnimbus_jose\+jwt1.2
connect2idnimbus_jose\+jwt1.3
connect2idnimbus_jose\+jwt1.4
connect2idnimbus_jose\+jwt1.5
connect2idnimbus_jose\+jwt1.6
connect2idnimbus_jose\+jwt1.7
connect2idnimbus_jose\+jwt1.8
connect2idnimbus_jose\+jwt1.9
connect2idnimbus_jose\+jwt1.9.1
connect2idnimbus_jose\+jwt1.10
connect2idnimbus_jose\+jwt1.11
connect2idnimbus_jose\+jwt1.12
connect2idnimbus_jose\+jwt2.0
connect2idnimbus_jose\+jwt2.0.1
connect2idnimbus_jose\+jwt2.1
connect2idnimbus_jose\+jwt2.1.1
connect2idnimbus_jose\+jwt2.2
connect2idnimbus_jose\+jwt2.3
connect2idnimbus_jose\+jwt2.4
connect2idnimbus_jose\+jwt2.5
connect2idnimbus_jose\+jwt2.6
connect2idnimbus_jose\+jwt2.7
connect2idnimbus_jose\+jwt2.8
connect2idnimbus_jose\+jwt2.9
connect2idnimbus_jose\+jwt2.10
connect2idnimbus_jose\+jwt2.10.1
connect2idnimbus_jose\+jwt2.11.0
connect2idnimbus_jose\+jwt2.12.0
connect2idnimbus_jose\+jwt2.13.0
connect2idnimbus_jose\+jwt2.13.1
connect2idnimbus_jose\+jwt2.14
connect2idnimbus_jose\+jwt2.15
connect2idnimbus_jose\+jwt2.15.1
connect2idnimbus_jose\+jwt2.15.2
connect2idnimbus_jose\+jwt2.16
connect2idnimbus_jose\+jwt2.17
connect2idnimbus_jose\+jwt2.17.1
connect2idnimbus_jose\+jwt2.17.2
connect2idnimbus_jose\+jwt2.18
connect2idnimbus_jose\+jwt2.18.1
connect2idnimbus_jose\+jwt2.18.2
connect2idnimbus_jose\+jwt2.19
connect2idnimbus_jose\+jwt2.19.1
connect2idnimbus_jose\+jwt2.20
connect2idnimbus_jose\+jwt2.21
connect2idnimbus_jose\+jwt2.22
connect2idnimbus_jose\+jwt2.22.1
connect2idnimbus_jose\+jwt2.23
connect2idnimbus_jose\+jwt2.24
connect2idnimbus_jose\+jwt2.25
connect2idnimbus_jose\+jwt2.26
connect2idnimbus_jose\+jwt2.26.1
connect2idnimbus_jose\+jwt3.0
connect2idnimbus_jose\+jwt3.1
connect2idnimbus_jose\+jwt3.1.1
connect2idnimbus_jose\+jwt3.1.2
connect2idnimbus_jose\+jwt3.2
connect2idnimbus_jose\+jwt3.2.1
connect2idnimbus_jose\+jwt3.2.2
connect2idnimbus_jose\+jwt3.3
connect2idnimbus_jose\+jwt3.4
connect2idnimbus_jose\+jwt3.5
connect2idnimbus_jose\+jwt3.6
connect2idnimbus_jose\+jwt3.7
connect2idnimbus_jose\+jwt3.8
connect2idnimbus_jose\+jwt3.8.1
connect2idnimbus_jose\+jwt3.8.2
connect2idnimbus_jose\+jwt3.9
connect2idnimbus_jose\+jwt3.9.1
connect2idnimbus_jose\+jwt3.9.2
connect2idnimbus_jose\+jwt3.10
connect2idnimbus_jose\+jwt4.0
connect2idnimbus_jose\+jwt4.0.1
connect2idnimbus_jose\+jwt4.1
connect2idnimbus_jose\+jwt4.1.1
connect2idnimbus_jose\+jwt4.2
connect2idnimbus_jose\+jwt4.3
connect2idnimbus_jose\+jwt4.3.1
connect2idnimbus_jose\+jwt4.4
connect2idnimbus_jose\+jwt4.5
connect2idnimbus_jose\+jwt4.6
connect2idnimbus_jose\+jwt4.7
connect2idnimbus_jose\+jwt4.8
connect2idnimbus_jose\+jwt4.9
connect2idnimbus_jose\+jwt4.10
connect2idnimbus_jose\+jwt4.11
connect2idnimbus_jose\+jwt4.11.1
connect2idnimbus_jose\+jwt4.11.2
connect2idnimbus_jose\+jwt4.12
connect2idnimbus_jose\+jwt4.13
connect2idnimbus_jose\+jwt4.13.1
connect2idnimbus_jose\+jwt4.14
connect2idnimbus_jose\+jwt4.15
connect2idnimbus_jose\+jwt4.15.1
connect2idnimbus_jose\+jwt4.16
connect2idnimbus_jose\+jwt4.16.1
connect2idnimbus_jose\+jwt4.16.2
connect2idnimbus_jose\+jwt4.17
connect2idnimbus_jose\+jwt4.18
connect2idnimbus_jose\+jwt4.19
connect2idnimbus_jose\+jwt4.20
connect2idnimbus_jose\+jwt4.21
connect2idnimbus_jose\+jwt4.22
connect2idnimbus_jose\+jwt4.23
connect2idnimbus_jose\+jwt4.24
connect2idnimbus_jose\+jwt4.25
connect2idnimbus_jose\+jwt4.26
connect2idnimbus_jose\+jwt4.26.1
connect2idnimbus_jose\+jwt4.27
connect2idnimbus_jose\+jwt4.27.1
connect2idnimbus_jose\+jwt4.28
connect2idnimbus_jose\+jwt4.29
connect2idnimbus_jose\+jwt4.30
connect2idnimbus_jose\+jwt4.31
connect2idnimbus_jose\+jwt4.31.1
connect2idnimbus_jose\+jwt4.32
connect2idnimbus_jose\+jwt4.33
connect2idnimbus_jose\+jwt4.34
connect2idnimbus_jose\+jwt4.34.1
connect2idnimbus_jose\+jwt4.34.2
connect2idnimbus_jose\+jwt4.35
connect2idnimbus_jose\+jwt4.36.1
connect2idnimbus_jose\+jwt4.37
connect2idnimbus_jose\+jwt4.37.1
connect2idnimbus_jose\+jwt4.38

References

CWEs

CWE-354

Verify integrity in audit chain (admin only). AS-IS.