HIGH7.5
GHSA-7g24-qg88-p43q
jose4j uses weak cryptographic algorithm
Quick fix
GHSA-7g24-qg88-p43q — org.bitbucket.b_c:jose4j: upgrade to the fixed version with the command below.
# pom.xml: bump <version>0.9.3</version> for org.bitbucket.b_c:jose4jDetails
jose4j before v0.9.3 allows attackers to set a low PBES2 iteration count of 1000 or less.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.bitbucket.b_c:jose4j
Introduced in:
0Fixed in: 0.9.3Fix
# pom.xml: bump <version>0.9.3</version> for org.bitbucket.b_c:jose4jReferences
- https://nvd.nist.gov/vuln/detail/CVE-2023-31582[ADVISORY]
- https://bitbucket.org/b_c/jose4j[PACKAGE]
- https://bitbucket.org/b_c/jose4j/commits/1929fe3[WEB]
- https://bitbucket.org/b_c/jose4j/issues/203/insecure-support-of-setting-pbe-less-then[WEB]
- https://github.com/KANIXB/JWTIssues/blob/main/jose4j%20issue.md[WEB]