​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-99xf-gfgx-9h82

Published

Last updated

https://images.chainguard.dev/security/CGA-99xf-gfgx-9h82
Package

apache-nifi

Latest Update
Pending upstream fix
Aliases
  • CVE-2023-51775
  • GHSA-6qvw-249j-h44c

Severity

6.5

Medium

CVSS V3

Summary

jose4j denial of service via specifically crafted JWE

Description

The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images