​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-7847-h394-6rg8

Published

Last updated

https://images.chainguard.dev/security/CGA-7847-h394-6rg8
Package

dependency-track

Latest Update
Fixed
Fixed Version

4.10.1-r3

Aliases
  • CVE-2023-52428
  • GHSA-gvpg-vgmx-xg6w

Severity

7.5

High

CVSS V3

Summary

Denial of Service in Connect2id Nimbus JOSE+JWT

Description

In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images