PT-2024-2567 · Unknown+2 · Erlang-Jose+2

P3Ngu1Nw

·

Published

2024-03-19

·

Updated

2024-08-02

·

CVE-2023-50966

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions erlang-jose versions through 1.11.6
Description The issue is related to an uncontrolled resource consumption in the erlang-jose module for JSON object signing and encryption for Erlang and Elixir languages. This can be exploited by a remote attacker to cause a denial of service through CPU consumption by using a large p2c (PBES2 Count) value in a JOSE header.
Recommendations For versions through 1.11.6, limit access to the vulnerable module and monitor usage to minimize the risk of exploitation. Await a patch for a permanent fix.

Exploit

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

AZL-39719
AZL-39857
BDU:2024-02605
CVE-2023-50966
GHSA-9MG4-V392-8J68

Affected Products

Debian
Red Os
Erlang-Jose