Junglewise Threat Intelligence

GO-2020-0011 - When decrypting JsonWebEncryption objects with multiple recipients or JsonWebSignature objects with multiple signatures the Decrypt and Veri

Severity: info · Published 2021-04-14

Technologies: github.com/square/go-jose (Go). Vendors: Go.

Executive brief

When decrypting JsonWebEncryption objects with multiple recipients or JsonWebSignature objects with multiple signatures the Decrypt and Verify methods do not indicate which recipient or signature was valid. This may lead a caller to rely on protected headers from an invalid recipient or signature.

Affected products

  • Go github.com/square/go-jose

Related threats