CVE-2025-45767

jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do not meet recommended security standards" does not reflect guidance in a final publication.
CVSS

No CVSS.

Configurations

No configuration.

History

11 Aug 2025, 20:15

Type Values Removed Values Added
References
  • () https://gist.github.com/ZupeiNie/705a606fbb99f3bb8c9b51e5bc13c91d?permalink_comment_id=5711572#gistcomment-5711572 -
  • () https://github.com/panva/jose/discussions/813 -

04 Aug 2025, 00:15

Type Values Removed Values Added
Summary jose v6.0.10 was discovered to contain weak encryption. jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do not meet recommended security standards" does not reflect guidance in a final publication.

01 Aug 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-01 15:15

Updated : 2025-08-11 20:15


NVD link : CVE-2025-45767

Mitre link : CVE-2025-45767


JSON object : View

Products Affected

No product.

CWE

No CWE.