{"api_version":"1","generated_at":"2026-07-23T15:12:33+00:00","cve":"CVE-2023-37464","urls":{"html":"https://cve.report/CVE-2023-37464","api":"https://cve.report/api/cve/CVE-2023-37464.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-37464","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-37464"},"summary":{"title":"CVE-2023-37464","description":"OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). The AES GCM decryption routine incorrectly uses the Tag length from the actual Authentication Tag provided in the JWE. The spec  says that a fixed length of 16 octets must be applied. Therefore this bug allows an attacker to provide a truncated Authentication Tag and to modify the JWE accordingly. Users should upgrade to a version >= 0.6.2.2. Users unable to upgrade should avoid using AES GCM encryption and replace it with another encryption algorithm (e.g. AES CBC).","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2023-07-14 21:15:00","updated_at":"2023-09-15 22:15:00"},"problem_types":["CWE-327"],"metrics":[],"references":[{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PTZHOVGY7AHGNMEY245HK4Q36AMA53AL/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PTZHOVGY7AHGNMEY245HK4Q36AMA53AL/","refsource":"MISC","tags":[],"title":"[SECURITY] Fedora 38 Update: cjose-0.6.2.2-2.fc38 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/OpenIDC/cjose/commit/7325e9a5e71e2fc0e350487ecac7d84acdf0ed5e","name":"https://github.com/OpenIDC/cjose/commit/7325e9a5e71e2fc0e350487ecac7d84acdf0ed5e","refsource":"MISC","tags":[],"title":"use fixed authentication tag length of 16 octets in AES GCM decryption · OpenIDC/cjose@7325e9a · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.debian.org/security/2023/dsa-5472","name":"https://www.debian.org/security/2023/dsa-5472","refsource":"MISC","tags":[],"title":"Debian -- Security Information -- DSA-5472-1 cjose","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.debian.org/debian-lts-announce/2023/08/msg00002.html","name":"https://lists.debian.org/debian-lts-announce/2023/08/msg00002.html","refsource":"MISC","tags":[],"title":"[SECURITY] [DLA 3515-1] cjose security update","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/OpenIDC/cjose/security/advisories/GHSA-3rhg-3gf2-6xgj","name":"https://github.com/OpenIDC/cjose/security/advisories/GHSA-3rhg-3gf2-6xgj","refsource":"MISC","tags":[],"title":"incorrect Authentication Tag length usage in AES GCM decryption · Advisory · OpenIDC/cjose · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFWAPMYYVBO2U65HPYDTBEKNSXG4TP5C/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFWAPMYYVBO2U65HPYDTBEKNSXG4TP5C/","refsource":"MISC","tags":[],"title":"[SECURITY] Fedora 37 Update: cjose-0.6.2.2-2.fc37 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LCQJXKDPCWCXB2V4JMQ3UWYJ4UIBPUW6/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LCQJXKDPCWCXB2V4JMQ3UWYJ4UIBPUW6/","refsource":"MISC","tags":[],"title":"[SECURITY] Fedora 39 Update: cjose-0.6.2.2-2.fc39 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/OpenIDC/cjose/releases/tag/v0.6.2.2","name":"https://github.com/OpenIDC/cjose/releases/tag/v0.6.2.2","refsource":"MISC","tags":[],"title":"Release release v0.6.2.2 · OpenIDC/cjose · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://datatracker.ietf.org/doc/html/rfc7518#section-4.7","name":"https://datatracker.ietf.org/doc/html/rfc7518#section-4.7","refsource":"MISC","tags":[],"title":"RFC 7518 - JSON Web Algorithms (JWA)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-37464","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-37464","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"37464","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"cjose","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2023-37464","qid":"160830","title":"Oracle Enterprise Linux Security Update for mod_auth_openidc:2.3 (ELSA-2023-4418)"},{"cve":"CVE-2023-37464","qid":"160832","title":"Oracle Enterprise Linux Security Update for cjose (ELSA-2023-4411)"},{"cve":"CVE-2023-37464","qid":"241881","title":"Red Hat Update for mod_auth_openidc:2.3 (RHSA-2023:4410)"},{"cve":"CVE-2023-37464","qid":"241883","title":"Red Hat Update for mod_auth_openidc:2.3 (RHSA-2023:4408)"},{"cve":"CVE-2023-37464","qid":"241884","title":"Red Hat Update for mod_auth_openidc:2.3 (RHSA-2023:4409)"},{"cve":"CVE-2023-37464","qid":"241887","title":"Red Hat Update for cjose (RHSA-2023:4411)"},{"cve":"CVE-2023-37464","qid":"241890","title":"Red Hat Update for mod_auth_openidc:2.3 (RHSA-2023:4418)"},{"cve":"CVE-2023-37464","qid":"241900","title":"Red Hat Update for cjose (RHSA-2023:4417)"},{"cve":"CVE-2023-37464","qid":"241903","title":"Red Hat Update for mod_auth_openidc:2.3 (RHSA-2023:4429)"},{"cve":"CVE-2023-37464","qid":"285272","title":"Fedora Security Update for cjose (FEDORA-2023-d5f23da04a)"},{"cve":"CVE-2023-37464","qid":"378750","title":"Alibaba Cloud Linux Security Update for mod_auth_openidc:2.3 (ALINUX3-SA-2023:0091)"},{"cve":"CVE-2023-37464","qid":"505990","title":"Alpine Linux Security Update for cjose"},{"cve":"CVE-2023-37464","qid":"6000119","title":"Debian Security Update for cjose (DLA 3515-1)"},{"cve":"CVE-2023-37464","qid":"6000213","title":"Debian Security Update for cjose (DSA 5472-1)"},{"cve":"CVE-2023-37464","qid":"754226","title":"SUSE Enterprise Linux Security Update for cjose (SUSE-SU-2023:3030-1)"},{"cve":"CVE-2023-37464","qid":"754257","title":"SUSE Enterprise Linux Security Update for cjose (SUSE-SU-2023:3230-1)"},{"cve":"CVE-2023-37464","qid":"941197","title":"AlmaLinux Security Update for mod_auth_openidc:2.3 (ALSA-2023:4418)"},{"cve":"CVE-2023-37464","qid":"941201","title":"AlmaLinux Security Update for cjose (ALSA-2023:4411)"},{"cve":"CVE-2023-37464","qid":"960964","title":"Rocky Linux Security Update for mod_auth_openidc:2.3 (RLSA-2023:4418)"}]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-37464","ASSIGNER":"security-advisories@github.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). The AES GCM decryption routine incorrectly uses the Tag length from the actual Authentication Tag provided in the JWE. The spec  says that a fixed length of 16 octets must be applied. Therefore this bug allows an attacker to provide a truncated Authentication Tag and to modify the JWE accordingly. Users should upgrade to a version >= 0.6.2.2. Users unable to upgrade should avoid using AES GCM encryption and replace it with another encryption algorithm (e.g. AES CBC)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-327: Use of a Broken or Risky Cryptographic Algorithm","cweId":"CWE-327"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"OpenIDC","product":{"product_data":[{"product_name":"cjose","version":{"version_data":[{"version_affected":"=","version_value":"< 0.6.2.2"}]}}]}}]}},"references":{"reference_data":[{"url":"https://github.com/OpenIDC/cjose/security/advisories/GHSA-3rhg-3gf2-6xgj","refsource":"MISC","name":"https://github.com/OpenIDC/cjose/security/advisories/GHSA-3rhg-3gf2-6xgj"},{"url":"https://github.com/OpenIDC/cjose/commit/7325e9a5e71e2fc0e350487ecac7d84acdf0ed5e","refsource":"MISC","name":"https://github.com/OpenIDC/cjose/commit/7325e9a5e71e2fc0e350487ecac7d84acdf0ed5e"},{"url":"https://datatracker.ietf.org/doc/html/rfc7518#section-4.7","refsource":"MISC","name":"https://datatracker.ietf.org/doc/html/rfc7518#section-4.7"},{"url":"https://github.com/OpenIDC/cjose/releases/tag/v0.6.2.2","refsource":"MISC","name":"https://github.com/OpenIDC/cjose/releases/tag/v0.6.2.2"},{"url":"https://lists.debian.org/debian-lts-announce/2023/08/msg00002.html","refsource":"MISC","name":"https://lists.debian.org/debian-lts-announce/2023/08/msg00002.html"},{"url":"https://www.debian.org/security/2023/dsa-5472","refsource":"MISC","name":"https://www.debian.org/security/2023/dsa-5472"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFWAPMYYVBO2U65HPYDTBEKNSXG4TP5C/","refsource":"MISC","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFWAPMYYVBO2U65HPYDTBEKNSXG4TP5C/"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PTZHOVGY7AHGNMEY245HK4Q36AMA53AL/","refsource":"MISC","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PTZHOVGY7AHGNMEY245HK4Q36AMA53AL/"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LCQJXKDPCWCXB2V4JMQ3UWYJ4UIBPUW6/","refsource":"MISC","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LCQJXKDPCWCXB2V4JMQ3UWYJ4UIBPUW6/"}]},"source":{"advisory":"GHSA-3rhg-3gf2-6xgj","discovery":"UNKNOWN"},"impact":{"cvss":[{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.6,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N","version":"3.1"}]}},"nvd":{"publishedDate":"2023-07-14 21:15:00","lastModifiedDate":"2023-09-15 22:15:00","problem_types":["CWE-327"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:cisco:cjose:*:*:*:*:*:*:*:*","versionEndExcluding":"0.6.2.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}