Vulnerabilities
Vulnerable Software
Jose-Php Project:  Security Vulnerabilities
The RSA 1.5 algorithm implementation in the JOSE_JWE class in JWE.php in jose-php before 2.2.1 lacks the Random Filling protection mechanism, which makes it easier for remote attackers to obtain cleartext data via a Million Message Attack (MMA).
CVSS Score
5.3
EPSS Score
0.005
Published
2016-09-03
jose-php before 2.2.1 does not use constant-time operations for HMAC comparison, which makes it easier for remote attackers to obtain sensitive information via a timing attack, related to JWE.php and JWS.php.
CVSS Score
3.7
EPSS Score
0.003
Published
2016-09-03


Contact Us

Shodan ® - All rights reserved