SCA: security update for jose, jose-browser-runtime, jose-node-cjs-runtime, jose-node-esm-runtime (GHSA-jv3g-j58f-9mq9)

medium Tenable Cloud Security Plugin ID 416579

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- JOSE is "JSON Web Almost Everything" - JWA, JWS, JWE, JWT, JWK, JWKS with no dependencies using runtime's
native crypto in Node.js, Browser, Cloudflare Workers, Electron, and Deno. The PBKDF2-based JWE key
management algorithms expect a JOSE Header Parameter named `p2c` PBES2 Count, which determines how many
PBKDF2 iterations must be executed in order to derive a CEK wrapping key. The purpose of this parameter is
to intentionally slow down the key derivation function in order to make password brute-force and
dictionary attacks more expensive. This makes the PBES2 algorithms unsuitable for situations where the JWE
is coming from an untrusted source: an adversary can intentionally pick an extremely high PBES2 Count
value, that will initiate a CPU-bound computation that may take an unreasonable amount of time to finish.
Under certain conditions, it is possible to have the user's environment consume unreasonable amount of CPU
time. The impact is limited only to users utilizing the JWE decryption APIs with symmetric secrets to
decrypt JWEs from untrusted parties who do not limit the accepted JWE Key Management Algorithms (`alg`
Header Parameter) using the `keyManagementAlgorithms` (or `algorithms` in v1.x) decryption option or
through other means. The `v1.28.2`, `v2.0.6`, `v3.20.4`, and `v4.9.2` releases limit the maximum PBKDF2
iteration count to `10000` by default. It is possible to adjust this limit with a newly introduced
`maxPBES2Count` decryption option. If users are unable to upgrade their required library version, they
have two options depending on whether they expect to receive JWEs using any of the three PBKDF2-based JWE
key management algorithms. They can use the `keyManagementAlgorithms` decryption option to disable
accepting PBKDF2 altogether, or they can inspect the JOSE Header prior to using the decryption API and
limit the PBKDF2 iteration count (`p2c` Header Parameter). (CVE-2022-36083)

See Also

https://github.com/advisories/GHSA-jv3g-j58f-9mq9

Plugin Details

Severity: Medium

ID: 416579

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2022-36083

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/16/2022

Vulnerability Publication Date: 9/7/2022

Reference Information

CVE: CVE-2022-36083