Lucene search

K
githubGitHub Advisory DatabaseGHSA-6QVW-249J-H44C
HistoryFeb 29, 2024 - 3:33 a.m.

jose4j denial of service via specifically crafted JWE

2024-02-2903:33:14
GitHub Advisory Database
github.com
16
jose4j
denial of service
crafted jwe
java
cpu consumption
pbes2 count
software

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

Affected configurations

Vulners
Node
org.bitbucket.b_c\Matchjose4j
CPENameOperatorVersion
org.bitbucket.b_c:jose4jlt0.9.4

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%