{"id":"GO-2020-0010","summary":"Elliptic curve key disclosure in github.com/square/go-jose","details":"When using ECDH-ES an attacker can mount an invalid curve attack during decryption as the supplied public key is not checked to be on the same curve as the receivers private key.","aliases":["CVE-2016-9121","GHSA-86r9-39j9-99wp"],"modified":"2024-05-20T16:03:47Z","published":"2021-04-14T20:04:52Z","database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2020-0010"},"references":[{"type":"FIX","url":"https://github.com/square/go-jose/commit/c7581939a3656bb65e89d64da0a52364a33d2507"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2016/11/03/1"}],"affected":[{"package":{"name":"github.com/square/go-jose","ecosystem":"Go","purl":"pkg:golang/github.com/square/go-jose"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.4"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/square/go-jose/cipher","symbols":["DeriveECDHES"]},{"path":"github.com/square/go-jose","symbols":["JsonWebEncryption.Decrypt","JsonWebKey.UnmarshalJSON","ecDecrypterSigner.decryptKey","rawJsonWebKey.ecPublicKey"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2020-0010.json"}}],"schema_version":"1.7.3","credits":[{"name":"Quan Nguyen from Google's Information Security Engineering Team"}]}