​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-hvjw-cqfw-cqf3

Published

Last updated

https://images.chainguard.dev/security/CGA-hvjw-cqfw-cqf3
Package

apache-nifi

Latest Update
Pending upstream fix
Aliases
  • CVE-2023-52428
  • GHSA-gvpg-vgmx-xg6w

Severity

7.5

High

CVSS V3

Summary

Denial of Service in Connect2id Nimbus JOSE+JWT

Description

In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images