A JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and node.js-based servers
80%
Total Score
48
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
CVE-2023-25653 node-jose is vulnerable to Loop with Unreachable Exit Condition ('Infinite Loop') in versions 0.0.0 - 2.2.0. | 0.0.0 - 2.2.0 | High |
CVE-2018-0114 node-jose is vulnerable to Improper Verification of Cryptographic Signature in versions 0.0.0 - 0.11.0. | 0.0.0 - 0.11.0 | High |
CVE-2017-16007 node-jose is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 0.9.3. | 0.0.0 - 0.9.3 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
long Version ^5.2.0 | — | — |
pako Version ^2.0.4 | — | — |
uuid Version ^9.0.0 | — | — |
buffer Version ^6.0.3 | — | — |
lodash Version ^4.17.21 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant