VDB
Sign up
HIGH7.5

GHSA-gvpg-vgmx-xg6w

Denial of Service in Connect2id Nimbus JOSE+JWT

Quick fix

GHSA-gvpg-vgmx-xg6w — com.nimbusds:nimbus-jose-jwt: upgrade to the fixed version with the command below.

# pom.xml: bump <version>9.37.2</version> for com.nimbusds:nimbus-jose-jwt

Details

In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/com.nimbusds:nimbus-jose-jwt
Introduced in: 0Fixed in: 9.37.2
Fix# pom.xml: bump <version>9.37.2</version> for com.nimbusds:nimbus-jose-jwt

References