j
jose project
Security Risk Profile
27
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 3 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 16, 2021 to present
3
Total CVEs
0
Critical+High
0
Exploited
0
Unpatched
Threat Assessment
Avg CVSS
5.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
27/100
low
Severity Distribution
Critical
0High
0Medium
3Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
No CWE data available
Most Affected Products
1. Jose Project Jose Node.js9
2. panva Jose Node.js7
3. npm/jose6
4. npm/jose-node-esm-runtime3
5. npm/jose-node-cjs-runtime3
Recent Vulnerabilities
See more →CVE-2024-28176
CVSS 5.9EPSS 0%medium
jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintext
Mar 7, 2024
CVE-2022-36083
CVSS 5.3medium
JOSE vulnerable to resource exhaustion via specifically crafted JWE
Sep 7, 2022
CVE-2021-29443
CVSS 5.9medium
Padding Oracle Attack due to Observable Timing Discrepancy in jose
Apr 16, 2021🔧 No Patch
Monitor jose project in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.