HIGH7.5
GHSA-gvpg-vgmx-xg6w
Denial of Service in Connect2id Nimbus JOSE+JWT
Quick fix
GHSA-gvpg-vgmx-xg6w — com.nimbusds:nimbus-jose-jwt: upgrade to the fixed version with the command below.
# pom.xml: bump <version>9.37.2</version> for com.nimbusds:nimbus-jose-jwtDetails
In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/com.nimbusds:nimbus-jose-jwt
Introduced in:
0Fixed in: 9.37.2Fix
# pom.xml: bump <version>9.37.2</version> for com.nimbusds:nimbus-jose-jwt