panva jose
cpe:2.3:a:jose_project:jose:*:*:*:*:node.js:*:*
- <= v6.0.10
A vulnerability exists in the Panva jose library version 6.0.10, where the encryption methods employed are considered weak. Specifically, the HMAC and RSA key lengths used in the library's JSON Web Signature (JWS) implementation do not adhere to recommended security standards, potentially leading to vulnerabilities and attacks.
The weak encryption can result in inadequate protection of data, allowing for possible decryption or manipulation of information that should be secure.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.