HIGH7.5
GHSA-3677-xxcr-wjqv
jose4j is vulnerable to DoS via compressed JWE content
Quick fix
GHSA-3677-xxcr-wjqv — org.bitbucket.b_c:jose4j: upgrade to the fixed version with the command below.
# pom.xml: bump <version>0.9.6</version> for org.bitbucket.b_c:jose4jDetails
In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.bitbucket.b_c:jose4j
Introduced in:
0Fixed in: 0.9.6Fix
# pom.xml: bump <version>0.9.6</version> for org.bitbucket.b_c:jose4j