​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-7x8r-hc4w-927c

Published

Last updated

https://images.chainguard.dev/security/CGA-7x8r-hc4w-927c
Package

stargate

Latest Update
Fixed
Fixed Version

1.0.79-r2

Aliases
  • CVE-2023-52428
  • GHSA-gvpg-vgmx-xg6w

Severity

7.5

High

CVSS V3

Summary

Denial of Service in Connect2id Nimbus JOSE+JWT

Description

In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images