Use of a Broken or Risky Cryptographic Algorithm in org.bitbucket.b_c:jose4j
Cx8bc13cba-30bf
- org.bitbucket.b_c:jose4j
Summary
RSA1_5 in jose4j is susceptible to chosen ciphertext attacks. The attack allows to decrypt "RSA1_5" or "RSA_OAEP" encrypted ciphertexts. It may be feasible to sign with affected keys. This vulnerability affects org.bitbucket.b_c:jose4j versions prior to 0.9.3.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- HIGH
- NONE
CWE-327 - Use of a Broken or Risky Cryptographic Algorithm
The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information.
References
Advisory Timeline
- Published