« Volver al listado

CVE-2016-9121

Estado: ModificadaCrítica (9.1)—

go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm. When deriving a shared key using ECDH-ES for an encrypted message, go-jose neglected to check that the received public key on a message is on the same curve as the static private key of the receiver, thus making it vulnerable to an invalid curve attack.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-9121",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "support@hackerone.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Go JOSE All versions before 1.0.4",
          "versions": [
            {
              "status": "affected",
              "version": "Go JOSE All versions before 1.0.4"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-03-28T02:59:00.213",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2016/11/03/1",
      "tags": [
        "Mailing List",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://github.com/square/go-jose/commit/c7581939a3656bb65e89d64da0a52364a33d2507",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://hackerone.com/reports/164590",
      "tags": [
        "Permissions Required"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2016/11/03/1",
      "tags": [
        "Mailing List",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/square/go-jose/commit/c7581939a3656bb65e89d64da0a52364a33d2507",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://hackerone.com/reports/164590",
      "tags": [
        "Permissions Required"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-326"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm. When deriving a shared key using ECDH-ES for an encrypted message, go-jose neglected to check that the received public key on a message is on the same curve as the static private key of the receiver, thus making it vulnerable to an invalid curve attack."
    },
    {
      "lang": "es",
      "value": "go-jose en versiones anteriores a 1.0.4 sufre de un ataque de curva no válida para el algoritmo ECDH-ES. Al derivar una clave compartida usando ECDH-ES para un mensaje encriptado, go-jose descuidado para comprobar que la clave pública recibida en un mensaje está en la misma curva que la clave privada estática del receptor, haciéndola vulnerable a una curva no válida ataque."
    }
  ],
  "lastModified": "2026-06-17T00:55:33.213",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:go-jose_project:go-jose:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "461700A0-1ABE-4A30-9C79-80C835D8B62E",
              "versionEndIncluding": "1.0.3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "support@hackerone.com"
}