CVE-2023-52428

In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.
Configurations

Configuration 1 (hide)

cpe:2.3:a:connect2id:nimbus_jose\+jwt:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-02-11 05:15

Updated : 2024-11-21 08:39


NVD link : CVE-2023-52428

Mitre link : CVE-2023-52428

CVE.ORG link : CVE-2023-52428


JSON object : View

Products Affected

connect2id

  • nimbus_jose\+jwt
CWE
NVD-CWE-noinfo CWE-770

Allocation of Resources Without Limits or Throttling