Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-50967

Опубликовано: 20 мар. 2024
Источник: redhat
CVSS3: 7.5

Описание

latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

A flaw was found in the Jose package, where a large number of iterations used to derive the wrapping key for the PBKDF2 algorithm may lead to a denial of service. This flaw allows an attacker to set a large number of `PBKDF2' iterations, triggering an uncontrolled resource consumption that impacts the availability of the targeted application.

Отчет

The JWE key management algorithms use a JOSE Header Parameter called p2c (PBES2 Count), which controls the PBKDF2 iterations to derive a CEK wrapping key. If an attacker sets p2c too high, it can lead to excessive computational use and a potential denial of service attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Will not fix
Multicluster Engine for Kubernetesmulticluster-engine/multicluster-engine-console-mce-rhel9Will not fix
OpenShift ServerlessjoseWill not fix
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel8Not affected
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Affected
Red Hat Enterprise Linux 10joseNot affected
Red Hat Enterprise Linux 7joseOut of support scope
Red Hat OpenShift Data Science (RHODS)rhods/odh-dashboard-rhel8Not affected
Red Hat OpenShift Data Science (RHODS)rhods/odh-operator-rhel8Not affected
Red Hat OpenShift Data Science (RHODS)rhods/odh-rhel8-operatorNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2270538jose: Denial of service due to uncontrolled CPU consumption

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

CVSS3: 7.5
nvd
больше 1 года назад

latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

CVSS3: 7.5
debian
больше 1 года назад

latchset jose through version 11 allows attackers to cause a denial of ...

CVSS3: 7.5
github
больше 1 года назад

latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

CVSS3: 7.5
fstec
больше 1 года назад

Уязвимость модуля языка С для подписи и шифрования объектов JSON latchset Jose, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3