Описание
Connect2id Nimbus JOSE + JWT before 10.0.2 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE: this is independent of the Gson 2.11.0 issue because the Connect2id product could have checked the JSON object nesting depth, regardless of what limits (if any) were imposed by Gson.
A denial of service flaw has been discovered in Connect2id Nimbus JOSE + JWT. This issue can allow a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Cryostat 4 | nimbus-jose-jwt | Fix deferred | ||
Logging Subsystem for Red Hat OpenShift | nimbus-jose-jwt | Fix deferred | ||
Red Hat AMQ Broker 7 | nimbus-jose-jwt | Fix deferred | ||
Red Hat build of Apache Camel 4 for Quarkus 3 | nimbus-jose-jwt | Fix deferred | ||
Red Hat build of Apache Camel for Spring Boot 4 | nimbus-jose-jwt | Fix deferred | ||
Red Hat build of Apache Camel - HawtIO 4 | nimbus-jose-jwt | Fix deferred | ||
Red Hat build of Apicurio Registry 2 | nimbus-jose-jwt | Fix deferred | ||
Red Hat build of Apicurio Registry 3 | nimbus-jose-jwt | Fix deferred | ||
Red Hat build of Quarkus | nimbus-jose-jwt | Fix deferred | ||
Red Hat Fuse 7 | nimbus-jose-jwt | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
5.8 Medium
CVSS3
Связанные уязвимости
Connect2id Nimbus JOSE + JWT before 10.0.2 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE: this is independent of the Gson 2.11.0 issue because the Connect2id product could have checked the JSON object nesting depth, regardless of what limits (if any) were imposed by Gson.
Connect2id Nimbus JOSE + JWT before 10.0.2 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE: this is independent of the Gson 2.11.0 issue because the Connect2id product could have checked the JSON object nesting depth, regardless of what limits (if any) were imposed by Gson.
Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON
EPSS
5.8 Medium
CVSS3