​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-7v5w-r37c-32w7

Published

Last updated

https://images.chainguard.dev/security/CGA-7v5w-r37c-32w7
Package

elasticsearch-7

Latest Update
Fixed
Fixed Version

7.17.20-r0

Aliases
  • CVE-2023-52428
  • GHSA-gvpg-vgmx-xg6w

Severity

7.5

High

CVSS V3

Summary

Denial of Service in Connect2id Nimbus JOSE+JWT

Description

In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images