Vulnerabilities > Cisco > Node Jose

DATE CVE VULNERABILITY TITLE RISK
2023-02-16 CVE-2023-25653 Infinite Loop vulnerability in Cisco Node-Jose
node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for web browsers and node.js-based servers.
network
low complexity
cisco CWE-835
7.5
2018-06-04 CVE-2017-16007 Unspecified vulnerability in Cisco Node-Jose
node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and node.js-based servers.
network
cisco
4.3
2018-01-04 CVE-2018-0114 Improper Verification of Cryptographic Signature vulnerability in Cisco Node-Jose
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens using a key that is embedded within the token.
network
low complexity
cisco CWE-347
5.0