Resource exhaustion in jose - CVE-2022-36083

 

Resource exhaustion in jose - CVE-2022-36083

Published: November 25, 2022


Vulnerability identifier: #VU69615
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-36083
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to the way application handles untrusted JWE tokens A remote attacker can trigger pass the PBKDF2-based JWE key with an extremely high PBES2 Count value and consume significant amount of CPU time, resulting in a denial of service conditions.


Affected software

jose
Cloud Pak for Security (CP4S)
Event Streams
IBM Cloud Pak for Watson AIOps
App Connect Enterprise Certified Container
Netcool Operations Insight

How to mitigate CVE-2022-36083

Install updates from vendor's website.

jose - addressed in versions 1.28.2, 2.0.6, 3.20.4, 4.9.2
Cloud Pak for Security (CP4S) - update to 1.10.7.0
IBM Cloud Pak for Watson AIOps - update to 3.5.1
Event Streams - update to 11.0.4
Netcool Operations Insight - update to 1.6.10

External References

Related Security Bulletins