Connect2id kayıtları
connect2id üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-354 Improper Validation of Integrity Check Value1
- CWE-755 Improper Handling of Exceptional Conditions1
- CWE-770 Allocation of Resources Without Limits or Throttling1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2019-17195Kavram kanıtı | Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crashconnect2id · nimbus jose\+jwt · CWE-755 | Kritik9,8 | — | %11,1 | 15 Eki 2019 |
30İzleyin | CVE-2017-12974İstismar yok | Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curveconnect2id · nimbus jose\+jwt · CWE-347 | Yüksek7,5 | — | %1,3 | 20 Ağu 2017 |
30İzleyin | CVE-2017-12972İstismar yok | In Nimbus JOSE+JWT before 4.39, there is no integer-overflow check when converting length values from bytes to bits, which allows attackers connect2id · nimbus jose\+jwt · CWE-345 | Yüksek7,5 | — | %0,9 | 20 Ağu 2017 |
30İzleyin | CVE-2023-52428İstismar yok | In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header valconnect2id · nimbus jose\+jwt · CWE-770 | Yüksek7,5 | — | %0,8 | 11 Şub 2024 |
12İzleyin | CVE-2017-12973İstismar yok | Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackeconnect2id · nimbus jose\+jwt · CWE-354 | Düşük3,1 | — | %0,6 | 20 Ağu 2017 |
- CVE-2019-1719542Planlayın
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash
KritikCVSS 9,8Kavram kanıtıEPSS %11connect2id · nimbus jose\+jwt15 Eki 2019
- CVE-2017-1297430İzleyin
Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve
YüksekCVSS 7,5İstismar yokEPSS %1connect2id · nimbus jose\+jwt20 Ağu 2017
- CVE-2017-1297230İzleyin
In Nimbus JOSE+JWT before 4.39, there is no integer-overflow check when converting length values from bytes to bits, which allows attackers
YüksekCVSS 7,5İstismar yokEPSS %1connect2id · nimbus jose\+jwt20 Ağu 2017
- CVE-2023-5242830İzleyin
In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header val
YüksekCVSS 7,5İstismar yokEPSS %1connect2id · nimbus jose\+jwt11 Şub 2024
- CVE-2017-1297312İzleyin
Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attacke
DüşükCVSS 3,1İstismar yokEPSS %1connect2id · nimbus jose\+jwt20 Ağu 2017