The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade jose
to version 1.28.1, 2.0.5, 3.11.4 or higher.
jose is an Universal 'JSON Web Almost Everything' - JWA, JWS, JWE, JWT, JWK with no dependencies
Affected versions of this package are vulnerable to Timing Attack. A difference in task execution timing may be observed in the AES_CBC_HMAC_SHA2 Algorithm when a padding error occurs during decryption, which may allow a malicious actor to decrypt data without the key.