Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

deps(server): CVE-2024-28176 #7717

Merged
merged 1 commit into from Mar 7, 2024
Merged

deps(server): CVE-2024-28176 #7717

merged 1 commit into from Mar 7, 2024

Conversation

etnoy
Copy link
Contributor

@etnoy etnoy commented Mar 7, 2024

jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintext A vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. This allows an adversary to exploit specific scenarios where the compression ratio becomes exceptionally high. As a result, the length of the JWE token, which is determined by the compressed content's size, can land below application-defined limits. In such cases, other existing application level mechanisms for preventing resource exhaustion may be rendered ineffective.

image

https://debricked.com/app/en/vulnerability/300278?repositoryId=72274&commitId=2489384

@etnoy etnoy added dependencies Pull requests that update a dependency file 🗄️server labels Mar 7, 2024
Copy link

Deploying with  Cloudflare Pages  Cloudflare Pages

Latest commit: 2f8c3f3
Status: ✅  Deploy successful!
Preview URL: https://2b8a70d7.immich.pages.dev
Branch Preview URL: https://deps-cve-2024-28176.immich.pages.dev

View logs

@jrasm91 jrasm91 merged commit f1a8e38 into main Mar 7, 2024
27 checks passed
@jrasm91 jrasm91 deleted the deps/CVE-2024-28176 branch March 7, 2024 20:34
aviv926 pushed a commit to aviv926/immich that referenced this pull request Mar 7, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file 🗄️server
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants