#VU98704 Resource exhaustion in erlang-jose - CVE-2023-50966
Published: October 16, 2024
erlang-jose
Andrew Bennett
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling large p2c (aka PBES2 Count) value in a JOSE header. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.