Executive brief
jose is a widely-used JavaScript library for cryptographic operations including JWE (JSON Web Encryption) decryption. A timing-based side-channel vulnerability allows attackers to decrypt confidential data protected by AES-CBC-HMAC algorithms without knowing the encryption key. By observing minute differences in how long decryption failures take, attackers can statistically infer the plaintext one byte at a time, potentially exposing sensitive authentication tokens or encrypted messages.
Technical details
The vulnerability is a classic padding oracle attack enabled by an observable timing discrepancy (CWE-208, CWE-696). When decrypting AES_CBC_HMAC_SHA2 ciphertexts (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512), the library performed both HMAC tag verification and CBC decryption before throwing JWEDecryptionFailed, but timing differences between HMAC failures and padding errors were observable to an attacker. No authentication is required—the attacker only needs network access to a service using vulnerable versions. An adversary can issue repeated decryption requests and measure response times to build a padding oracle, enabling decryption of arbitrary JWE payloads with ~128*b calls per ciphertext block. The fix verifies the HMAC tag before performing CBC decryption, eliminating the timing side-channel. Patched versions are ^1.28.1, ^2.0.5, and >=3.11.4.
Affected products
- panva jose <1.28.1 || >=2.0.0 and <2.0.5 || >=3.0.0 and <3.11.4
Timeline
- 2021-04-15: disclosed: GitHub security advisory published
- 2021-04-15: patched: Patches released: v1.28.1, v2.0.5, v3.11.4