VDB
CVE-2024-28122
CVE-2024-28122
PUBLISHED
CVSS 6.800000190734863 MEDIUM
JWX vulnerable to a denial of service attack using compressed JWE message
EPSS 0.57% · 44.9th percentile
Risk Scores
CVSS 3.1
6.800000190734863
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
EPSS Score
0.57%
44.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | lestrrat-go/jwx/v2 | 0, 0, 0 |
| lestrrat-go | jwx | *, 2.0.0, >= 2.0.0, < 2.0.21 |
| lestrrat-go | jwx | 1.2.0, 2.0.0, 1.2.0 |
| github.com | lestrrat-go/jwx | 0, 0, 0 |
Timeline
- Jan 21, 1970 Security Advisory
- Mar 8, 2024 CVE Published
- Mar 9, 2024 EPSS Score
- Mar 9, 2024 PoC Published
- Mar 9, 2024 PoC Published
- Mar 10, 2024 PoC Published
- Mar 11, 2024 CVE Updated
- Apr 4, 2024 EPSS Score
- May 1, 2024 EPSS Score
- May 27, 2024 EPSS Score
- Jun 23, 2024 EPSS Score
- Jul 19, 2024 EPSS Score
References
- https://github.com/lestrrat-go/jwx/releases/tag/v2.0.21 url
- https://github.com/lestrrat-go/jwx/security/advisories/GHSA-hj3v-m684-v259 url
- https://github.com/lestrrat-go/jwx/releases/tag/v1.2.29 url
- https://github.com/lestrrat-go/jwx package
- https://nvd.nist.gov/vuln/detail/CVE-2024-28122 advisory
- https://github.com/lestrrat-go/jwx/commit/d01027d74c7376d66037a10f4f64af9af26a7e34 url
- https://github.com/lestrrat-go/jwx/commit/d43f2ceb7f0c13714dfe8854d6439766e86faa76 url