← Back

CVE-2024-28180

nvd nist
Published: Mar 9, 2024Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Exploitability: 2.8 / Impact: 1.4
Source: security-advisories@github.com (Secondary)

Description

Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.

Affected (4)

Go Jose
1 product
Fedora
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Go Jose Project
From 2.0.0 to 2.6.3
From 3.0.0 to 3.0.3
From 4.0.0 to 4.0.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
From 38 to 40

References (26)

Source: security-advisories@github.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.