Jose-php Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 2
    Known Exploited: 0
    0
    Critical Level Threats
    0
    High Level Threats
    1
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2016-5429

    jose-php before 2.2.1 does not use constant-time operations for HMAC comparison, which makes it easier for remote attackers to obtain sensitive information via a timing attack, related to JWE.php and JWS.php.

    Last Modified: Apr 12, 2025
    Published: Sep 03, 2016

    CVE-2016-5430

    The RSA 1.5 algorithm implementation in the JOSE_JWE class in JWE.php in jose-php before 2.2.1 lacks the Random Filling protection mechanism, which makes it easier for remote attackers to obtain cleartext data via a Million Message Attack (MMA).

    Last Modified: Apr 12, 2025
    Published: Sep 03, 2016
    Items Per Page
    Jose-Php_Project Vulnerabilities & Security CVEs | CVE-DB