GO-2020-0009

    Dashboard / Vulnerabilities / GO-2020-0009

    GO-2020-0009

    Published: 14 Apr 2021Last Modified: 20 May 2024

    Summary: Integer overflow in github.com/square/go-jose

    Details: On 32-bit platforms an attacker can manipulate a ciphertext encrypted with AES-CBC with HMAC such that they can control how large the input buffer is when computing the HMAC authentication tag. This can can allow a manipulated ciphertext to be verified as authentic, opening the door for padding oracle attacks.

    Affected packages

    Package

    Name: github.com/square/go-jose

    Purl: pkg:golang/github.com/square/go-jose

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.0.0-20160903044734-789a4c4bd4c1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GO-2020-0009 | CVE-DB