Executive brief
Decompression bomb vulnerability in github.com/go-jose/go-jose
Affected products
- Go gopkg.in/square/go-jose.v2
- Go github.com/go-jose/go-jose/v4
- Go github.com/go-jose/go-jose/v3
- Go gopkg.in/go-jose/go-jose.v2
Junglewise Threat Intelligence
CVE-2024-28180 · Severity: low · CVSS 3.1 · Published 2024-03-15
Technologies: github.com/go-jose/go-jose/v4 (Go), github.com/go-jose/go-jose/v3 (Go). Vendors: Go.
Decompression bomb vulnerability in github.com/go-jose/go-jose