CVE-2023-50658Allocation of Resources Without Limits or Throttling in Dvsekhvalnov Jose2go

Severity
7.5HIGHNVD
EPSS
0.1%
top 83.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 29

Description

The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages7 packages

Patches

🔴Vulnerability Details

5
OSV
CVE-2023-50658: The jose2go component before 12024-02-29
OSV
jose2go vulnerable to denial of service via large p2c value2024-02-29
GHSA
jose2go vulnerable to denial of service via large p2c value2024-02-29
OSV
Duplicate Advisory: Denial of service when decrypting attack controlled input in github.com/dvsekhvalnov/jose2go2023-12-20
OSV
Denial of service when decrypting attacker controlled input in github.com/dvsekhvalnov/jose2go2023-12-20

📋Vendor Advisories

2
Microsoft
The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.2023-12-12
Debian
CVE-2023-50658: golang-github-dvsekhvalnov-jose2go - The jose2go component before 1.6.0 for Go allows attackers to cause a denial of ...2023