{"id":"GHSA-h6wq-jw7q-grxv","summary":"Elliptic Curve Key Disclosure","details":"Affected versions of the package are vulnerable to Elliptic Curve Key Disclosure.","modified":"2024-12-01T05:28:15.001015Z","published":"2021-02-24T19:38:21Z","withdrawn":"2021-02-24T19:38:21Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2019-05-23T07:37:09Z","nvd_published_at":null,"cwe_ids":[]},"references":[{"type":"WEB","url":"https://bitbucket.org/b_c/jose4j/commits/0517896170af8d5c057407c70a7b08dae454829e"},{"type":"WEB","url":"https://www.whitesourcesoftware.com/vulnerability-database/WS-2017-0208"}],"affected":[{"package":{"name":"org.bitbucket.b_c:jose4j","ecosystem":"Maven","purl":"pkg:maven/org.bitbucket.b_c/jose4j"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.3.6"},{"fixed":"0.5.5"}]}],"versions":["0.3.6","0.3.7","0.3.8","0.3.9","0.4.0","0.4.1","0.4.2","0.4.3","0.4.4","0.5.0","0.5.1","0.5.2","0.5.3","0.5.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-h6wq-jw7q-grxv/GHSA-h6wq-jw7q-grxv.json"}}],"schema_version":"1.9.0"}