CVE-2024-28180
Decompression bomb vulnerability in github.com/go-jose/go-jose
4.3
MEDIUM
CVSS 3.1
EPSS 2.0%
描述
Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.
如何修補 CVE-2024-28180
要修補 CVE-2024-28180,請將受影響套件升級到下列已修補版本。
- —升級至 4.0.1-1 或更新版本
- —未列出修補版本
- —升級至 3.0.3 或更新版本
- —升級至 3.0.3 或更新版本
- —升級至 4.0.1 或更新版本
- —升級至 4.0.1 或更新版本
- —升級至 2.6.3 或更新版本
- —升級至 2.6.3 或更新版本
- —未列出修補版本
- —未列出修補版本
CVE-2024-28180 正在被利用嗎?
低 — EPSS 為 2.0%,目前沒有觀察到大規模利用活動。
受影響套件(10)
- from 0, < 4.0.1-1
- from 0
- from 0, < 3.0.3
- from 0, < 3.0.3
- from 0, < 4.0.1
- from 0, < 4.0.1
- from 0, < 2.6.3
- from 0, < 2.6.3
- from 0, <= 2.6.0
- from 0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |