jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less.
References
Link | Resource |
---|---|
https://bitbucket.org/b_c/jose4j/issues/203/insecure-support-of-setting-pbe-less-then | Issue Tracking |
https://github.com/KANIXB/JWTIssues/blob/main/jose4j%20issue.md | Third Party Advisory |
https://bitbucket.org/b_c/jose4j/issues/203/insecure-support-of-setting-pbe-less-then | Issue Tracking |
https://github.com/KANIXB/JWTIssues/blob/main/jose4j%20issue.md | Third Party Advisory |
Configurations
History
21 Nov 2024, 08:02
Type | Values Removed | Values Added |
---|---|---|
References | () https://bitbucket.org/b_c/jose4j/issues/203/insecure-support-of-setting-pbe-less-then - Issue Tracking | |
References | () https://github.com/KANIXB/JWTIssues/blob/main/jose4j%20issue.md - Third Party Advisory |
Information
Published : 2023-10-25 18:17
Updated : 2024-11-21 08:02
NVD link : CVE-2023-31582
Mitre link : CVE-2023-31582
CVE.ORG link : CVE-2023-31582
JSON object : View
Products Affected
jose4j_project
- jose4j
CWE
CWE-331
Insufficient Entropy