Bug 2268820 (CVE-2024-28176) - CVE-2024-28176 jose: resource exhaustion
Summary: CVE-2024-28176 jose: resource exhaustion
Keywords:
Status: NEW
Alias: CVE-2024-28176
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2268823 2268824 2268825 2268826 2268827 2268828 2268829 2268830 2268831 2268832 2268833 2268834 2268835 2268836 2268837 2268838 2268839 2268840 2268841 2268842 2268843 2268844 2268845 2268847 2268848 2268849 2268850 2268851 2268852 2268857 2268858 2268860 2268861 2268862 2268863 2268864 2268865 2268866 2268867 2268868 2268869 2268906 2268907 2268908 2299671 2306539
Blocks: 2268846
TreeView+ depends on / blocked
 
Reported: 2024-03-10 20:00 UTC by ybuenos
Modified: 2025-05-06 08:28 UTC (History)
89 users (show)

Fixed In Version: jose 2.0.7, jose 4.15.5
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2024:3978 0 None None None 2024-06-18 09:34:32 UTC
Red Hat Product Errata RHBA-2024:4109 0 None None None 2024-06-26 01:10:08 UTC
Red Hat Product Errata RHBA-2024:4195 0 None None None 2024-07-01 07:33:59 UTC
Red Hat Product Errata RHBA-2024:4196 0 None None None 2024-07-01 07:45:41 UTC
Red Hat Product Errata RHSA-2024:0041 0 None None None 2024-06-27 11:24:25 UTC
Red Hat Product Errata RHSA-2024:0045 0 None None None 2024-06-27 13:01:35 UTC
Red Hat Product Errata RHSA-2024:3826 0 None None None 2024-06-11 19:40:51 UTC
Red Hat Product Errata RHSA-2024:3827 0 None None None 2024-06-11 19:41:14 UTC
Red Hat Product Errata RHSA-2024:3968 0 None None None 2024-06-18 00:29:21 UTC
Red Hat Product Errata RHSA-2024:4591 0 None None None 2024-07-17 13:15:32 UTC
Red Hat Product Errata RHSA-2024:5094 0 None None None 2024-08-07 15:39:47 UTC
Red Hat Product Errata RHSA-2024:5294 0 None None None 2024-08-13 15:26:08 UTC
Red Hat Product Errata RHSA-2024:6755 0 None None None 2024-09-18 11:57:32 UTC
Red Hat Product Errata RHSA-2024:8676 0 None None None 2024-10-30 14:26:56 UTC
Red Hat Product Errata RHSA-2024:9181 0 None None None 2024-11-12 09:02:33 UTC

Description ybuenos 2024-03-10 20:00:44 UTC
jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has 
 been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for decompressing plaintext after its decryption. Under certain conditions it is possible to have the user's environment consume unreasonable amount of CPU time or memory during JWE Decryption operations. This issue has been patched in versions 2.0.7 and 4.15.5.

https://github.com/panva/jose/commit/02a65794f7873cdaf12e81e80ad076fcdc4a9314
https://github.com/panva/jose/commit/1b91d88d2f8233f3477a5f4579aa5f8057b2ee8b
https://github.com/panva/jose/security/advisories/GHSA-hhhv-q57g-882q

Comment 1 ybuenos 2024-03-10 20:07:44 UTC
Created apptainer tracking bugs for this issue:

Affects: epel-all [bug 2268823]
Affects: fedora-all [bug 2268827]


Created buildah tracking bugs for this issue:

Affects: fedora-all [bug 2268828]


Created caddy tracking bugs for this issue:

Affects: epel-all [bug 2268824]
Affects: fedora-all [bug 2268829]


Created containerd tracking bugs for this issue:

Affects: fedora-all [bug 2268830]


Created cri-o tracking bugs for this issue:

Affects: fedora-all [bug 2268831]


Created cri-o:1.21/cri-o tracking bugs for this issue:

Affects: epel-all [bug 2268825]


Created cri-o:1.22/cri-o tracking bugs for this issue:

Affects: fedora-all [bug 2268832]


Created cri-o:1.23/cri-o tracking bugs for this issue:

Affects: fedora-all [bug 2268833]


Created cri-o:1.24/cri-o tracking bugs for this issue:

Affects: fedora-all [bug 2268834]


Created cri-o:1.25/cri-o tracking bugs for this issue:

Affects: fedora-all [bug 2268835]


Created cri-o:1.26/cri-o tracking bugs for this issue:

Affects: fedora-all [bug 2268836]


Created cri-o:1.27/cri-o tracking bugs for this issue:

Affects: fedora-all [bug 2268837]


Created golang-github-acme-lego tracking bugs for this issue:

Affects: fedora-all [bug 2268838]


Created golang-github-in-toto tracking bugs for this issue:

Affects: fedora-all [bug 2268839]


Created golang-github-jose-3 tracking bugs for this issue:

Affects: fedora-all [bug 2268840]


Created golang-github-letsencrypt-pebble tracking bugs for this issue:

Affects: fedora-all [bug 2268841]


Created golang-gopkg-square-jose-2 tracking bugs for this issue:

Affects: fedora-all [bug 2268842]


Created grafana tracking bugs for this issue:

Affects: fedora-all [bug 2268843]


Created jose tracking bugs for this issue:

Affects: fedora-all [bug 2268852]


Created moby-engine tracking bugs for this issue:

Affects: fedora-all [bug 2268844]


Created osbuild-composer tracking bugs for this issue:

Affects: fedora-all [bug 2268845]


Created podman tracking bugs for this issue:

Affects: fedora-all [bug 2268847]


Created podman-tui tracking bugs for this issue:

Affects: fedora-all [bug 2268848]


Created prometheus-podman-exporter tracking bugs for this issue:

Affects: fedora-all [bug 2268849]


Created singularity-ce tracking bugs for this issue:

Affects: epel-all [bug 2268826]
Affects: fedora-all [bug 2268850]


Created skopeo tracking bugs for this issue:

Affects: fedora-all [bug 2268851]

Comment 8 Lokesh Mandvekar 2024-03-11 10:03:28 UTC
@ybuenos I see a bunch of bzs filed against go-based packages which have go-jose in their go.mod files. But the github advisory page linked in description doesn't mention anything about go-jose. Is there any guidance available on how to handle go-jose, assuming go-jose is affected at all?

Comment 10 Lokesh Mandvekar 2024-03-12 09:55:56 UTC
The go-jose advisory is at https://github.com/go-jose/go-jose/security/advisories/GHSA-c5q2-7r4c-mv6g

Comment 20 errata-xmlrpc 2024-06-11 19:40:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2024:3826 https://access.redhat.com/errata/RHSA-2024:3826

Comment 21 errata-xmlrpc 2024-06-11 19:41:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2024:3827 https://access.redhat.com/errata/RHSA-2024:3827

Comment 22 errata-xmlrpc 2024-06-18 00:29:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2024:3968 https://access.redhat.com/errata/RHSA-2024:3968

Comment 23 errata-xmlrpc 2024-06-27 11:24:18 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.16

Via RHSA-2024:0041 https://access.redhat.com/errata/RHSA-2024:0041

Comment 24 errata-xmlrpc 2024-06-27 13:01:28 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.16

Via RHSA-2024:0045 https://access.redhat.com/errata/RHSA-2024:0045

Comment 26 errata-xmlrpc 2024-07-17 13:15:26 UTC
This issue has been addressed in the following products:

  RHODF-4.16-RHEL-9

Via RHSA-2024:4591 https://access.redhat.com/errata/RHSA-2024:4591

Comment 27 errata-xmlrpc 2024-08-07 15:39:41 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Service Mesh 2.6 for RHEL 8
  Red Hat OpenShift Service Mesh 2.6 for RHEL 9

Via RHSA-2024:5094 https://access.redhat.com/errata/RHSA-2024:5094

Comment 28 errata-xmlrpc 2024-08-13 15:26:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2024:5294 https://access.redhat.com/errata/RHSA-2024:5294

Comment 29 errata-xmlrpc 2024-09-18 11:57:25 UTC
This issue has been addressed in the following products:

  RHODF-4.16-RHEL-9

Via RHSA-2024:6755 https://access.redhat.com/errata/RHSA-2024:6755

Comment 30 errata-xmlrpc 2024-10-30 14:26:48 UTC
This issue has been addressed in the following products:

  RHODF-4.17-RHEL-9

Via RHSA-2024:8676 https://access.redhat.com/errata/RHSA-2024:8676

Comment 31 Borja Tarraso 2024-11-08 15:26:00 UTC
This issue has been solved in RHACM 2.10.1 with this public advisory https://access.redhat.com/errata/RHBA-2024:1793

Comment 32 Borja Tarraso 2024-11-08 15:37:20 UTC
This issue has been solved in RHACM 2.9.4 via this public advisory https://access.redhat.com/errata/RHBA-2024:3593

Comment 33 Borja Tarraso 2024-11-08 15:39:42 UTC
This issue has been solved in MCE 2.5.2 via this public advisory https://access.redhat.com/errata/RHBA-2024:1775

Comment 34 Borja Tarraso 2024-11-08 16:06:59 UTC
This issue has been solved in MCE 2.4.5 via this public advisory https://access.redhat.com/errata/RHBA-2024:3555

Comment 35 errata-xmlrpc 2024-11-12 09:02:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2024:9181 https://access.redhat.com/errata/RHSA-2024:9181


Note You need to log in before you can comment on or make changes to this bug.