DirectorySecurity advisories
Sign in

Security advisories

GHSA-2c7c-3mj9-8fqh

Published

Last updated

https://github.com/advisories/GHSA-2c7c-3mj9-8fqh

Description

Decryption of malicious PBES2 JWE objects can consume unbounded system resources. The go-jose package is subject to a "billion hashes attack" causing denial-of-service when decrypting JWE inputs. This occurs when an attacker can provide a PBES2 encrypted JWE blob with a very large p2c value that, when decrypted, produces a denial-of-service.

References

  • https://github.com/go-jose/go-jose/issues/64

Affected packages

Advisories are based on vulnerability information provided by Grype from Anchore.

Products

Chainguard Images

© 2024 Chainguard, Inc.