VDB
Sign up
MEDIUM6.5

GHSA-6qvw-249j-h44c

jose4j denial of service via specifically crafted JWE

Quick fix

GHSA-6qvw-249j-h44c — org.bitbucket.b_c:jose4j: upgrade to the fixed version with the command below.

# pom.xml: bump <version>0.9.4</version> for org.bitbucket.b_c:jose4j

Details

The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.bitbucket.b_c:jose4j
Introduced in: 0Fixed in: 0.9.4
Fix# pom.xml: bump <version>0.9.4</version> for org.bitbucket.b_c:jose4j

References