VDB
Sign up
HIGH7.5

GHSA-3677-xxcr-wjqv

jose4j is vulnerable to DoS via compressed JWE content

Quick fix

GHSA-3677-xxcr-wjqv — org.bitbucket.b_c:jose4j: upgrade to the fixed version with the command below.

# pom.xml: bump <version>0.9.6</version> for org.bitbucket.b_c:jose4j

Details

In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.bitbucket.b_c:jose4j
Introduced in: 0Fixed in: 0.9.6
Fix# pom.xml: bump <version>0.9.6</version> for org.bitbucket.b_c:jose4j

References