Resource exhaustion in jwt - CVE-2025-30204

 

Resource exhaustion in jwt - CVE-2025-30204

Published: March 24, 2025


Vulnerability identifier: #VU105983
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-30204
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources within the parse.ParseUnverified function when parsing authorization header. A remote attacker can send a specially crafted HTTP response to the application, trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

jwt
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP6
Oracle Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Fedora
Red Hat Enterprise Linux Server - AUS
Server Applications Module
Basesystem Module
Containers Module
openSUSE Leap
Db2 Intelligence Center
DB2 Data Management Console
Guardium Data Security Center (GDSC)
Security QRadar EDR
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Storage Scale
Storage Ceph
Db2 Big SQL
Maximo Application Suite - Visual Inspection Component
Business Automation Insights
Netcool Operations Insight
IBM Fusion HCI
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
OpenShift Logging
IBM Maximo Application Suite
Submariner
IBM Observability with Instana
Multicluster GlobalHub
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Dev Spaces
Cryostat
IBM Cloud Pak for Business Automation
watsonx.data
IBM Cloud Pak System
Multicluster Engine for Kubernetes
OpenShift Data Foundation (formerly OpenShift Container Storage)
Financial Transaction Manager
Splunk Enterprise
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
thrift (Red Hat package)
restic
opentelemetry-collector (Red Hat package)
ansible-collection-ansible-posix (Red Hat package)
rekor-debuginfo
rekor
libunwind (Red Hat package)
opentofu
amber-cli
rclone
liborc (Red Hat package)
nvml (Red Hat package)
oath-toolkit (Red Hat package)
gperftools (Red Hat package)
lttng-ust (Red Hat package)
golang-github-prometheus
etcdctl
etcd
protobuf (Red Hat package)
ansible-collection-community-general (Red Hat package)
cephadm-ansible (Red Hat package)
incus
libarrow (Red Hat package)
grafana (Red Hat package)
ceph (Red Hat package)
docker-stable-bash-completion
docker-stable-debuginfo
docker-stable
docker-stable-fish-completion
docker-stable-zsh-completion
docker-stable-rootless-extras
moby-engine
osbuild-composer (Red Hat package)
osbuild-composer-worker
osbuild-composer
osbuild-composer-core
re2 (Red Hat package)
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat Ceph Storage

How to mitigate CVE-2025-30204

Install updates from vendor's website.

jwt - addressed in versions 4.5.2, 5.2.2
Db2 Intelligence Center - update to 1.1.1.0
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.2
IBM Fusion HCI - update to 2.10.0
IBM Cloud Pak System - update to 2.3.6.1
Multicluster Engine for Kubernetes - addressed in versions 2.4.9, 2.5.9, 2.6.8, 2.8.3, 2.8.4
DB2 Data Management Console - update to 3.1.13.2
Financial Transaction Manager - addressed in versions 3.2.13 iFix4, 4.0.6.0 iFix5, 4.0.7.0
Guardium Data Security Center (GDSC) - update to 3.7.2
Security QRadar EDR - update to 3.12.18
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
Storage Scale - update to 5.2.3.3
OpenShift Logging - addressed in versions 5.9.13, 6.0.7, 6.0.12, 6.1.5, 6.2.7
Storage Ceph - update to 7.1z6
Db2 Big SQL - update to 8.2
Maximo Application Suite - Visual Inspection Component - addressed in versions 8.9.19, 9.0.16, 9.1.7
IBM Maximo Application Suite - addressed in versions 8.10.30, 8.11.27, 9.0.16, 9.1.5
Splunk Enterprise - addressed in versions 9.3.10, 9.4.9, 10.0.4, 10.2.1
Business Automation Insights - update to 25.0.0.0.1
thrift (Red Hat package) - addressed in versions 0.15.0-3.el9cp, 0.20.0-4.el10cp
Submariner - addressed in versions 0.17.6, 0.18.5, 0.19.4, 0.20.1
restic - update to 0.18.0-1.fc43
opentelemetry-collector (Red Hat package) - update to 0.107.0-8.el9_4
IBM Observability with Instana - update to 1.0.295
ansible-collection-ansible-posix (Red Hat package) - addressed in versions 1.2.0-1.3.el9ost, 2.0.0-1.el10cp
Multicluster GlobalHub - addressed in versions 1.2.3, 1.4.1
OpenShift API for Data Protection (OADP) - addressed in versions 1.3.7, 1.4.5
rekor-debuginfo - update to 1.3.10-150400.4.25.1
rekor - update to 1.3.10-150400.4.25.1
libunwind (Red Hat package) - addressed in versions 1.6.2-2.el9cp, 1.8.0-4.el10cp
Migration Toolkit for Containers - update to 1.8.7
opentofu - addressed in versions 1.9.1-1.fc43, 1.10.3-1.el9
amber-cli - update to 1.13.1+git20250329.c2e3bb8-150600.3.3.1
rclone - update to 1.70.2-1.fc43
liborc (Red Hat package) - update to 2.0.3-2.el10cp
nvml (Red Hat package) - update to 2.1.0-3.el10cp
oath-toolkit (Red Hat package) - addressed in versions 2.6.12-1.el9cp, 2.6.12-1.el10cp
gperftools (Red Hat package) - addressed in versions 2.9.1-5.el9cp, 2.9.1-5.el10cp
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.9.9, 2.10.8, 2.11.7, 2.13.3
lttng-ust (Red Hat package) - update to 2.13.7-5.el10cp
golang-github-prometheus - update to 2.55.1-1.fc43
etcdctl - update to 3.5.21-150000.7.12.1
etcd - update to 3.5.21-150000.7.12.1
protobuf (Red Hat package) - update to 3.19.6-12.el10
Red Hat OpenShift Dev Spaces - update to 3.21.0
Cryostat - update to 4.0.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4, 4.15.14, 4.17.7, 4.18
ansible-collection-community-general (Red Hat package) - addressed in versions 4.0.0-1.1.el9ost, 10.7.3-1.el10cp
cephadm-ansible (Red Hat package) - addressed in versions 4.1.4-1.el9cp, 4.1.4-1.el10cp
Red Hat OpenShift Container Platform - addressed in versions 4.12.76, 4.13.58, 4.14.50, 4.14.51, 4.14.52, 4.14.54, 4.15.49, 4.15.50, 4.15.53, 4.16.39, 4.17.24, 4.17.25, 4.17.26, 4.17.27, 4.18.8, 4.18.9, 4.18.10, 4.18.11, 4.18.17
incus - addressed in versions 6.12-1.fc41, 6.12-1.fc42
Red Hat Ceph Storage - addressed in versions 8.1, 9.0
libarrow (Red Hat package) - addressed in versions 9.0.0-10.el9cp, 15.0.2-3.el10cp
grafana (Red Hat package) - addressed in versions 9.0.9-6.el9_2, 10.2.6-9.el9_5, 10.2.6-11.el9_6
ceph (Red Hat package) - addressed in versions 20.1.0-144.el9cp, 20.1.0-144.el10cp
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF006, 24.0.1-IF005, 25.0.0-IF001
docker-stable-bash-completion - addressed in versions 24.0.9_ce-1.29.1, 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.36.1, 24.0.9_ce-150000.1.39.1
docker-stable-debuginfo - addressed in versions 24.0.9_ce-1.29.1, 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.36.1, 24.0.9_ce-150000.1.39.1
docker-stable - addressed in versions 24.0.9_ce-1.29.1, 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.36.1, 24.0.9_ce-150000.1.39.1
docker-stable-fish-completion - addressed in versions 24.0.9_ce-150000.1.36.1, 24.0.9_ce-150000.1.39.1
docker-stable-zsh-completion - addressed in versions 24.0.9_ce-150000.1.36.1, 24.0.9_ce-150000.1.39.1
docker-stable-rootless-extras - addressed in versions 24.0.9_ce-150000.1.36.1, 24.0.9_ce-150000.1.39.1
moby-engine - update to 28.2.2-1.fc43
osbuild-composer (Red Hat package) - addressed in versions 46.3-3.el9_0, 75-3.el8_8, 76.1-1.el9_2, 101-3.el8_10, 101.3-1.el9_4, 118.2-1.el9_5
osbuild-composer-worker - addressed in versions 118.2-1.0.1, 132.2-1.0.1
osbuild-composer - addressed in versions 118.2-1.0.1, 132.2-1.0.1
osbuild-composer-core - addressed in versions 118.2-1.0.1, 132.2-1.0.1
re2 (Red Hat package) - addressed in versions 20211101-4.el9cp, 20211101-4.el10cp

External References

Related Security Bulletins