PT-2024-2483 · Unknown+7 · Latchset Jose+7
P3Ngu1Nw
·
Published
2024-03-20
·
Updated
2025-12-03
·
CVE-2023-50967
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
latchset Jose versions prior to 11
Description
The issue is related to an uncontrolled resource consumption in the latchset Jose module for signing and encrypting JSON objects. This can be exploited by an attacker to cause a denial of service through CPU consumption by using a large
p2c (also known as PBES2 Count) value.Recommendations
For versions prior to 11, consider restricting the use of large
p2c values to minimize the risk of exploitation until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Red Hat
Red Os
Rocky Linux
Latchset Jose