Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Kanii

#32756de 53,635
7.8CVSS total
Vulnerabilidades · 1
PT-2023-8391
7.8
2023-01-20
Jose4J · Jose4J · CVE-2023-31582
**Name of the Vulnerable Software and Affected Versions** jose4j versions prior to 0.9.3 **Description** The issue is related to the use of an algorithm that provides insufficient entropy. This allows attackers to set a low iteration count of 1000 or less, potentially enabling them to bypass security restrictions. **Recommendations** For versions prior to 0.9.3, update to version 0.9.3 or later to resolve the issue. As a temporary workaround, consider increasing the PBES2 iteration count to a value greater than 1000 to minimize the risk of exploitation.