Weak Encryption Vulnerability in JOSE Product by Panva
CVE-2025-45767

7HIGH

Key Information:

Vendor

Panva

Status
Vendor
CVE Published:
1 August 2025

What is CVE-2025-45767?

The JOSE library version 6.0.10, developed by Panva, has been identified with a vulnerability stemming from weak encryption practices. This flaw can potentially expose sensitive data to unauthorized access, thereby compromising the security integrity of applications using this version. It is highly recommended to update to a patched version to mitigate potential risks associated with this vulnerability.

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.