Executive brief
node-jose is a JavaScript library that implements JSON Object Signing and Encryption (JOSE) for securing API communications and data integrity. When using its non-default fallback cryptographic backend (in environments without WebCrypto or Node.js crypto module), improper handling of modular inverse calculations in elliptic curve cryptography can cause an infinite loop, crashing the service and making it unavailable to legitimate users.
Technical details
The vulnerability exists in the fallback elliptic curve cryptography implementation (lib/deps/ecc/math.js) used when WebCrypto and Node.js crypto modules are unavailable. The root cause is improper handling of negative results from the jsbn library's modInverse function. When modInverse returns a negative value (mathematically correct but requiring special handling), the barrettReduce function fails to handle it correctly, causing an infinite loop. This affects EC key generation, ECDSA signing/verification, and ECDH key agreement. For random EC operations, triggering the bug requires a random bad value (probability ~2^-20); for ECDSA verification and ECDH, attackers can provide malicious points to trigger it. The vulnerability requires the fallback crypto backend to be active; environments with WebCrypto or Node.js crypto are unaffected. A fix is available in version 2.2.0.
Affected products
- Cisco node-jose < 2.2.0
Timeline
- 2023-02-16: disclosed