Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-52428

Опубликовано: 11 фев. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.

A vulnerability was found in the Nimbus Jose JWT package. By crafting a JWE with an excessively large p2c value, an attacker can trigger significant resource consumption during decryption, potentially leading to application slowdown or unavailability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 3com.nimbusds/nimbus-jose-jwtNot affected
Logging Subsystem for Red Hat OpenShiftcom.nimbusds/nimbus-jose-jwtAffected
Red Hat AMQ Broker 7com.nimbusds/nimbus-jose-jwtWill not fix
Red Hat build of Apache Camel 4 for Quarkus 3com.nimbusds/nimbus-jose-jwtNot affected
Red Hat build of Apache Camel for Spring Boot 3com.nimbusds/nimbus-jose-jwtAffected
Red Hat build of Apache Camel - HawtIO 4com.nimbusds/nimbus-jose-jwtAffected
Red Hat build of Apicurio Registry 2com.nimbusds/nimbus-jose-jwtAffected
Red Hat Build of Keycloakcom.nimbusds/nimbus-jose-jwtNot affected
Red Hat build of Quarkuscom.nimbusds/nimbus-jose-jwtNot affected
Red Hat Fuse 7com.nimbusds/nimbus-jose-jwtWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2309764nimbus-jose-jwt: large JWE p2c header value causes Denial of Service

EPSS

Процентиль: 23%
0.00078
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 2 года назад

In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.

CVSS3: 7.5
github
почти 2 года назад

Denial of Service in Connect2id Nimbus JOSE+JWT

CVSS3: 7.5
fstec
почти 2 года назад

Уязвимость компонента PasswordBasedDecrypter Java-библиотеки Nimbus JOSE + JWT, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 23%
0.00078
Низкий

7.5 High

CVSS3