Resource exhaustion in jose2go - CVE-2023-50658
Published: October 15, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can pass a large p2c value to the application, trigger excessive CPU consumption and perform a denial of service (DoS) attack.
Affected software
Splunk Enterprise
Fedora
golang-github-dvsekhvalnov-jose2go
How to mitigate CVE-2023-50658
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
golang-github-dvsekhvalnov-jose2go - update to 1.7.0-1.fc41