CVE-2017-12974
Last modified
CVE-2017-12974 is a vulnerability of currently unknown severity. Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve, which allows attackers to conduct an Invalid Curve Attack in environments where the JCE provider lacks the applicable curve validation.. EPSS estimates a 1.26% chance of exploitation in the next 30 days.
Description
Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve, which allows attackers to conduct an Invalid Curve Attack in environments where the JCE provider lacks the applicable curve validation.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Connect2id | Nimbus Jose\+Jwt | 1.0 |
| Connect2id | Nimbus Jose\+Jwt | 1.1 |
| Connect2id | Nimbus Jose\+Jwt | 1.2 |
| Connect2id | Nimbus Jose\+Jwt | 1.3 |
| Connect2id | Nimbus Jose\+Jwt | 1.4 |
| Connect2id | Nimbus Jose\+Jwt | 1.5 |
| Connect2id | Nimbus Jose\+Jwt | 1.6 |
| Connect2id | Nimbus Jose\+Jwt | 1.7 |
| Connect2id | Nimbus Jose\+Jwt | 1.8 |
| Connect2id | Nimbus Jose\+Jwt | 1.9 |
| Connect2id | Nimbus Jose\+Jwt | 1.9.1 |
| Connect2id | Nimbus Jose\+Jwt | 1.10 |
| Connect2id | Nimbus Jose\+Jwt | 1.11 |
| Connect2id | Nimbus Jose\+Jwt | 1.12 |
| Connect2id | Nimbus Jose\+Jwt | 2.0 |
| Connect2id | Nimbus Jose\+Jwt | 2.0.1 |
| Connect2id | Nimbus Jose\+Jwt | 2.1 |
| Connect2id | Nimbus Jose\+Jwt | 2.1.1 |
| Connect2id | Nimbus Jose\+Jwt | 2.2 |
| Connect2id | Nimbus Jose\+Jwt | 2.3 |
| Connect2id | Nimbus Jose\+Jwt | 2.4 |
| Connect2id | Nimbus Jose\+Jwt | 2.5 |
| Connect2id | Nimbus Jose\+Jwt | 2.6 |
| Connect2id | Nimbus Jose\+Jwt | 2.7 |
| Connect2id | Nimbus Jose\+Jwt | 2.8 |
| Connect2id | Nimbus Jose\+Jwt | 2.9 |
| Connect2id | Nimbus Jose\+Jwt | 2.10 |
| Connect2id | Nimbus Jose\+Jwt | 2.10.1 |
| Connect2id | Nimbus Jose\+Jwt | 2.11.0 |
| Connect2id | Nimbus Jose\+Jwt | 2.12.0 |
| Connect2id | Nimbus Jose\+Jwt | 2.13.0 |
| Connect2id | Nimbus Jose\+Jwt | 2.13.1 |
| Connect2id | Nimbus Jose\+Jwt | 2.14 |
| Connect2id | Nimbus Jose\+Jwt | 2.15 |
| Connect2id | Nimbus Jose\+Jwt | 2.15.1 |
| Connect2id | Nimbus Jose\+Jwt | 2.15.2 |
| Connect2id | Nimbus Jose\+Jwt | 2.16 |
| Connect2id | Nimbus Jose\+Jwt | 2.17 |
| Connect2id | Nimbus Jose\+Jwt | 2.17.1 |
| Connect2id | Nimbus Jose\+Jwt | 2.17.2 |
| Connect2id | Nimbus Jose\+Jwt | 2.18 |
| Connect2id | Nimbus Jose\+Jwt | 2.18.1 |
| Connect2id | Nimbus Jose\+Jwt | 2.18.2 |
| Connect2id | Nimbus Jose\+Jwt | 2.19 |
| Connect2id | Nimbus Jose\+Jwt | 2.19.1 |
| Connect2id | Nimbus Jose\+Jwt | 2.20 |
| Connect2id | Nimbus Jose\+Jwt | 2.21 |
| Connect2id | Nimbus Jose\+Jwt | 2.22 |
| Connect2id | Nimbus Jose\+Jwt | 2.22.1 |
| Connect2id | Nimbus Jose\+Jwt | 2.23 |
Showing 50 of 123 affected configurations. See NVD for the full list.
References
- https://bitbucket.org/connect2id/nimbus-jose-jwt/issues/217/explicit-check-for-ec-public-key-on-curvePatch, Third Party Advisory
- https://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/CHANGELOG.txtRelease Notes, Third Party Advisory
- https://bitbucket.org/connect2id/nimbus-jose-jwt/issues/217/explicit-check-for-ec-public-key-on-curvePatch, Third Party Advisory
- https://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/CHANGELOG.txtRelease Notes, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-12974?
How severe is CVE-2017-12974?
How do I fix CVE-2017-12974?
Are you affected by CVE-2017-12974?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
