Vulnerability Description
In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Connect2Id | Nimbus Jose\+Jwt | < 9.37.2 |
Related Weaknesses (CWE)
References
- https://bitbucket.org/connect2id/nimbus-jose-jwt/commits/3b3b77ePatch
- https://bitbucket.org/connect2id/nimbus-jose-jwt/issues/526/Issue Tracking
- https://connect2id.com/products/nimbus-jose-jwtProduct
- https://bitbucket.org/connect2id/nimbus-jose-jwt/commits/3b3b77ePatch
- https://bitbucket.org/connect2id/nimbus-jose-jwt/issues/526/Issue Tracking
- https://connect2id.com/products/nimbus-jose-jwtProduct
FAQ
What is CVE-2023-52428?
CVE-2023-52428 is a vulnerability with a CVSS score of 7.5 (HIGH). In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBK...
How severe is CVE-2023-52428?
CVE-2023-52428 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-52428?
Check the references section above for vendor advisories and patch information. Affected products include: Connect2Id Nimbus Jose\+Jwt.