← Back

Jose Php

jose-php

Vendor: Jose Php Project • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jose Php Project
1Jose Php
May 6, 2026
Sep 3, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The RSA 1.5 algorithm implementation in the JOSE_JWE class in JWE.php in jose-php before 2.2.1 lacks the Random Filling protection mechanism, which makes it easier for remote attackers to obtain cleartext data via a Mill...Show more
The RSA 1.5 algorithm implementation in the JOSE_JWE class in JWE.php in jose-php before 2.2.1 lacks the Random Filling protection mechanism, which makes it easier for remote attackers to obtain cleartext data via a Million Message Attack (MMA).Show less
1Jose Php Project
1Jose Php
May 6, 2026
Sep 3, 2016
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
jose-php before 2.2.1 does not use constant-time operations for HMAC comparison, which makes it easier for remote attackers to obtain sensitive information via a timing attack, related to JWE.php and JWS.php.