Insecure digital certificates In com.nimbusds:nimbus-jose-jwt
Description
Improper Verification of Cryptographic Signature in Nimbus JOSE+JWT Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve, which allows attackers to conduct an Invalid Curve Attack in environments where the JCE provider lacks the applicable curve validation.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 4.36 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4.