jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less.
References
Link | Resource |
---|---|
https://bitbucket.org/b_c/jose4j/issues/203/insecure-support-of-setting-pbe-less-then | Issue Tracking |
https://github.com/KANIXB/JWTIssues/blob/main/jose4j%20issue.md | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-10-25 18:17
Updated : 2023-10-31 15:18
NVD link : CVE-2023-31582
Mitre link : CVE-2023-31582
CVE.ORG link : CVE-2023-31582
JSON object : View
Products Affected
jose4j_project
- jose4j
CWE
CWE-331
Insufficient Entropy