Записи Connect2id
5 опубликованных записей вендора connect2id.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-354 Improper Validation of Integrity Check Value1
- CWE-755 Improper Handling of Exceptional Conditions1
- CWE-770 Allocation of Resources Without Limits or Throttling1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2019-17195Proof of concept | Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crashconnect2id · nimbus jose\+jwt · CWE-755 | Критическая9,8 | — | 11,1 % | 15 окт. 2019 г. |
30Наблюдать | CVE-2017-12974Эксплойта нет | Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curveconnect2id · nimbus jose\+jwt · CWE-347 | Высокая7,5 | — | 1,3 % | 20 авг. 2017 г. |
30Наблюдать | CVE-2017-12972Эксплойта нет | In Nimbus JOSE+JWT before 4.39, there is no integer-overflow check when converting length values from bytes to bits, which allows attackers connect2id · nimbus jose\+jwt · CWE-345 | Высокая7,5 | — | 0,9 % | 20 авг. 2017 г. |
30Наблюдать | CVE-2023-52428Эксплойта нет | In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header valconnect2id · nimbus jose\+jwt · CWE-770 | Высокая7,5 | — | 0,8 % | 11 февр. 2024 г. |
12Наблюдать | CVE-2017-12973Эксплойта нет | Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackeconnect2id · nimbus jose\+jwt · CWE-354 | Низкая3,1 | — | 0,6 % | 20 авг. 2017 г. |
- CVE-2019-1719542В плане
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash
КритическаяCVSS 9,8Proof of conceptEPSS 11 %connect2id · nimbus jose\+jwt15 окт. 2019 г.
- CVE-2017-1297430Наблюдать
Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %connect2id · nimbus jose\+jwt20 авг. 2017 г.
- CVE-2017-1297230Наблюдать
In Nimbus JOSE+JWT before 4.39, there is no integer-overflow check when converting length values from bytes to bits, which allows attackers
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %connect2id · nimbus jose\+jwt20 авг. 2017 г.
- CVE-2023-5242830Наблюдать
In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header val
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %connect2id · nimbus jose\+jwt11 февр. 2024 г.
- CVE-2017-1297312Наблюдать
Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attacke
НизкаяCVSS 3,1Эксплойта нетEPSS 1 %connect2id · nimbus jose\+jwt20 авг. 2017 г.