Skip to main content

Use of a Broken or Risky Cryptographic Algorithm in org.bitbucket.b_c:jose4j

Cx8bc13cba-30bf

  • org.bitbucket.b_c:jose4j
Severity High
Score 7.5/10

Summary

RSA1_5 in jose4j is susceptible to chosen ciphertext attacks. The attack allows to decrypt "RSA1_5" or "RSA_OAEP" encrypted ciphertexts. It may be feasible to sign with affected keys. This vulnerability affects org.bitbucket.b_c:jose4j versions prior to 0.9.3.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-327 - Use of a Broken or Risky Cryptographic Algorithm

The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information.

Advisory Timeline

  • Published