#VU87615 Resource exhaustion in Nimbus JOSE+JWT - CVE-2023-52428
Published: March 19, 2024 / Updated: November 20, 2024
Nimbus JOSE+JWT
Connect2id Ltd.
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper validation of user requests by the PasswordBasedDecrypter (PBKDF2) component. A remote attacker can send a specially crafted request using a large JWE p2c header, trigger resource exhaustion and perform a denial of service (DoS) attack.