CVE-2017-12974

UnknownEPSS 1.26%

Last modified

CVE-2017-12974 is a vulnerability of currently unknown severity. Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve, which allows attackers to conduct an Invalid Curve Attack in environments where the JCE provider lacks the applicable curve validation.. EPSS estimates a 1.26% chance of exploitation in the next 30 days.

Description

Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve, which allows attackers to conduct an Invalid Curve Attack in environments where the JCE provider lacks the applicable curve validation.

Metrics

EPSS Probability
1.26%

65.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Connect2idNimbus Jose\+Jwt1.0
Connect2idNimbus Jose\+Jwt1.1
Connect2idNimbus Jose\+Jwt1.2
Connect2idNimbus Jose\+Jwt1.3
Connect2idNimbus Jose\+Jwt1.4
Connect2idNimbus Jose\+Jwt1.5
Connect2idNimbus Jose\+Jwt1.6
Connect2idNimbus Jose\+Jwt1.7
Connect2idNimbus Jose\+Jwt1.8
Connect2idNimbus Jose\+Jwt1.9
Connect2idNimbus Jose\+Jwt1.9.1
Connect2idNimbus Jose\+Jwt1.10
Connect2idNimbus Jose\+Jwt1.11
Connect2idNimbus Jose\+Jwt1.12
Connect2idNimbus Jose\+Jwt2.0
Connect2idNimbus Jose\+Jwt2.0.1
Connect2idNimbus Jose\+Jwt2.1
Connect2idNimbus Jose\+Jwt2.1.1
Connect2idNimbus Jose\+Jwt2.2
Connect2idNimbus Jose\+Jwt2.3
Connect2idNimbus Jose\+Jwt2.4
Connect2idNimbus Jose\+Jwt2.5
Connect2idNimbus Jose\+Jwt2.6
Connect2idNimbus Jose\+Jwt2.7
Connect2idNimbus Jose\+Jwt2.8
Connect2idNimbus Jose\+Jwt2.9
Connect2idNimbus Jose\+Jwt2.10
Connect2idNimbus Jose\+Jwt2.10.1
Connect2idNimbus Jose\+Jwt2.11.0
Connect2idNimbus Jose\+Jwt2.12.0
Connect2idNimbus Jose\+Jwt2.13.0
Connect2idNimbus Jose\+Jwt2.13.1
Connect2idNimbus Jose\+Jwt2.14
Connect2idNimbus Jose\+Jwt2.15
Connect2idNimbus Jose\+Jwt2.15.1
Connect2idNimbus Jose\+Jwt2.15.2
Connect2idNimbus Jose\+Jwt2.16
Connect2idNimbus Jose\+Jwt2.17
Connect2idNimbus Jose\+Jwt2.17.1
Connect2idNimbus Jose\+Jwt2.17.2
Connect2idNimbus Jose\+Jwt2.18
Connect2idNimbus Jose\+Jwt2.18.1
Connect2idNimbus Jose\+Jwt2.18.2
Connect2idNimbus Jose\+Jwt2.19
Connect2idNimbus Jose\+Jwt2.19.1
Connect2idNimbus Jose\+Jwt2.20
Connect2idNimbus Jose\+Jwt2.21
Connect2idNimbus Jose\+Jwt2.22
Connect2idNimbus Jose\+Jwt2.22.1
Connect2idNimbus Jose\+Jwt2.23

Showing 50 of 123 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-12974?
Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve, which allows attackers to conduct an Invalid Curve Attack in environments where the JCE provider lacks the applicable curve validation.
How severe is CVE-2017-12974?
Severity scoring for CVE-2017-12974 is pending analysis. The EPSS model estimates a 1.26% probability of exploitation in the next 30 days.
How do I fix CVE-2017-12974?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-12974?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST