CVE-2025-45767: Weak Encryption
jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do not meet recommended security standards" does not reflect guidance in a final publication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-45767?
CVE-2025-45767 has been classified as having a high severity due to its weak encryption vulnerable to exploitation.
How do I fix CVE-2025-45767?
To fix CVE-2025-45767, upgrade to a later version of the jose library that addresses the weak encryption issue.
What are the potential impacts of CVE-2025-45767?
The potential impacts of CVE-2025-45767 include data breaches due to compromised encryption security.
Which versions of jose are affected by CVE-2025-45767?
CVE-2025-45767 affects jose version 6.0.10 and potentially earlier versions that utilize weak encryption.
Is CVE-2025-45767 being actively exploited?
As of the last security reports, there have been no confirmed active exploits for CVE-2025-45767, but caution is advised.