Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-50966

Опубликовано: 19 мар. 2024
Источник: debian
EPSS Низкий

Описание

erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
erlang-josefixed1.11.10-1package
erlang-joseno-dsabookwormpackage
erlang-joseno-dsabullseyepackage
erlang-josepostponedbusterpackage

Примечания

  • https://github.com/potatosalad/erlang-jose/issues/156

  • https://github.com/P3ngu1nW/CVE_Request/blob/main/erlang-jose.md

  • https://github.com/potatosalad/erlang-jose/commit/718d213f07b08056737923f8063d5df56dcb66ae (1.11.7)

EPSS

Процентиль: 3%
0.00019
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header.

CVSS3: 6.5
redhat
больше 1 года назад

erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header.

CVSS3: 5.3
nvd
больше 1 года назад

erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header.

CVSS3: 5.3
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 5.3
github
больше 1 года назад

erlang-jose vulnerable to denial of service via large p2c value

EPSS

Процентиль: 3%
0.00019
Низкий