PT-2023-8747 · Jose4J · Jose4J
Jesse Yang
·
Published
2023-12-03
·
Updated
2025-05-08
·
CVE-2023-51775
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
jose4j versions prior to 0.9.4
Description
The issue is related to the improper implementation of the PBES2 algorithm in the jose4j component when handling the
p2c parameter. This can allow a remote attacker to cause a denial of service due to CPU consumption via a large p2c (aka PBES2 Count) value.Recommendations
For versions prior to 0.9.4, update to version 0.9.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
p2c parameter to minimize the risk of exploitation.Exploit
Fix
DoS
Use of a Broken Cryptographic Algorithm
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jose4J