Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

okta-sdk-golang v2.20.0, high risk vulnerabilities with go.jose dependency #424

Open
shikhargiri opened this issue Jan 25, 2024 · 3 comments
Labels
bug Something isn't working stale

Comments

@shikhargiri
Copy link

Describe the bug?

Detailed paths
Introduced through: github.com/okta/[email protected] › github.com/go-jose/[email protected]

Security information
Factors contributing to the scoring:
Snyk: CVSS 7.5 - High Severity

NVD: NVD only publishes analysis of vulnerabilities which are assigned a CVE ID. This vulnerability currently does not have an assigned CVE ID.
Why are the scores different? Learn how Snyk evaluates vulnerability scores

Overview
Affected versions of this package are vulnerable to Denial of Service (DoS) when decrypting JWE inputs. An attacker can cause a denial-of-service by providing a PBES2 encrypted JWE blob with a very large p2c value.

What is expected to happen?

We are considering OKTA to release an stable version with the fix for this findings.

What is the actual behavior?

Overview
Affected versions of this package are vulnerable to Denial of Service (DoS) when decrypting JWE inputs. An attacker can cause a denial-of-service by providing a PBES2 encrypted JWE blob with a very large p2c value.

Reproduction Steps?

This vulnerabilities dependency was identified from OKTA library we are using.

Additional Information?

No response

Golang Version

1.21.4

SDK Version

OS version

No response

@shikhargiri shikhargiri added the bug Something isn't working label Jan 25, 2024
Copy link

github-actions bot commented Feb 9, 2024

This issue has been marked stale because there has been no activity within the last 14 days. To keep this issue active, remove the stale label.

Copy link

This issue has been marked stale because there has been no activity within the last 14 days. To keep this issue active, remove the stale label.

Copy link

This issue has been marked stale because there has been no activity within the last 14 days. To keep this issue active, remove the stale label.

@github-actions github-actions bot added the stale label Mar 26, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working stale
Projects
None yet
Development

No branches or pull requests

2 participants