Vulnerabilities (CVE)

Filtered by vendor Jose4j Project Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-51775 1 Jose4j Project 1 Jose4j 2025-05-08 N/A 6.5 MEDIUM
The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
CVE-2023-31582 1 Jose4j Project 1 Jose4j 2024-11-21 N/A 7.5 HIGH
jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less.