CVE-2017-12974
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/08/2017
Last modified:
20/04/2025
Description
Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve, which allows attackers to conduct an Invalid Curve Attack in environments where the JCE provider lacks the applicable curve validation.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:connect2id:nimbus_jose\+jwt:1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:connect2id:nimbus_jose\+jwt:1.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:connect2id:nimbus_jose\+jwt:1.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:connect2id:nimbus_jose\+jwt:1.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:connect2id:nimbus_jose\+jwt:1.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:connect2id:nimbus_jose\+jwt:1.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:connect2id:nimbus_jose\+jwt:1.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:connect2id:nimbus_jose\+jwt:1.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:connect2id:nimbus_jose\+jwt:1.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:connect2id:nimbus_jose\+jwt:1.9:*:*:*:*:*:*:* | ||
| cpe:2.3:a:connect2id:nimbus_jose\+jwt:1.9.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:connect2id:nimbus_jose\+jwt:1.10:*:*:*:*:*:*:* | ||
| cpe:2.3:a:connect2id:nimbus_jose\+jwt:1.11:*:*:*:*:*:*:* | ||
| cpe:2.3:a:connect2id:nimbus_jose\+jwt:1.12:*:*:*:*:*:*:* | ||
| cpe:2.3:a:connect2id:nimbus_jose\+jwt:2.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://bitbucket.org/connect2id/nimbus-jose-jwt/commits/f3a7a801f0c6b078899fed9226368eb7b44e2b2f
- https://bitbucket.org/connect2id/nimbus-jose-jwt/issues/217/explicit-check-for-ec-public-key-on-curve
- https://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/CHANGELOG.txt
- https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E
- https://bitbucket.org/connect2id/nimbus-jose-jwt/commits/f3a7a801f0c6b078899fed9226368eb7b44e2b2f
- https://bitbucket.org/connect2id/nimbus-jose-jwt/issues/217/explicit-check-for-ec-public-key-on-curve
- https://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/CHANGELOG.txt
- https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E



