Cryptographic issues in Nimbus JOSE+JWT - CVE-2017-12974
Published: January 10, 2020
Vulnerability details
The vulnerability allows a remote attacker to conduct a padding oracle attack.
The vulnerability exists due to Nimbus JOSE+JWT proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve. A remote attacker can conduct an Invalid Curve Attack in environments where the JCE provider lacks the applicable curve validation.
Affected software
IBM PureData System for Operational Analytics
IBM Engineering Requirements Management DOORS Next
How to mitigate CVE-2017-12974
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
External References
- https://bitbucket.org/connect2id/nimbus-jose-jwt/commits/f3a7a801f0c6b078899fed9226368eb7b44e2b2f
- https://bitbucket.org/connect2id/nimbus-jose-jwt/issues/217/explicit-check-for-ec-public-key-on-curve
- https://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/CHANGELOG.txt
- https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E