Lucene search

K
osvGoogleOSV:GHSA-GVPG-VGMX-XG6W
HistoryFeb 11, 2024 - 6:30 a.m.

Denial of Service in Connect2id Nimbus JOSE+JWT

2024-02-1106:30:27
Google
osv.dev
15
connect2id
nimbus jose+jwt
denial of service
vulnerability
passwordbaseddecrypter
pbkdf2

AI Score

7

Confidence

High

EPSS

0

Percentile

15.5%

In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.

AI Score

7

Confidence

High

EPSS

0

Percentile

15.5%