CVE-2023-52428
11.02.2024, 05:15
In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.Enginsight
Vendor | Product | Version |
---|---|---|
connect2id | nimbus_jose\+jwt | 𝑥 < 9.37.2 |
𝑥
= Vulnerable software versions
References