A number of JSON libraries using the JWE specification to create, sign and encrypt access tokens have been patched against an attack that allows for the recovery of a private key. Adobe researcher Antonio Sanso of Adobe said the libraries were vulnerable to the known Invalid Curve Attack if the libraries implement JWE for encryption with Key Agreement with Elliptic Curve Diffie-Hellman Ephemeral Static (ECDH-ES) Sanso wrote in a technical description of the attack published this week that an attacker, or sender, could extract a receiver s private key.
Source: https://threatpost.com/json-libraries-patched-against-invalid-curve-crypto-attack/124336/

