CVE-2023-52428
published 2024-02-11CVE-2023-52428: In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration…
PriorityP434high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.81%
52.9th percentile
In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | jira_service_management | — | — |
| connect2id | nimbus_jose_+jwt | < 9.37.2 | 9.37.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Analytics Risk Matrix: Analytics Server (Nimbus JOSE+JWT) — CVE-2023-52428
vendor_oracle·2025-04-15·CVSS 7.5
CVE-2023-52428 [HIGH] Oracle Oracle Analytics Risk Matrix: Analytics Server (Nimbus JOSE+JWT) — CVE-2023-52428
Oracle Oracle Analytics Risk Matrix: Analytics Server (Nimbus JOSE+JWT) vulnerability
CVE: CVE-2023-52428
CVSS: 7.5
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Graal Development Kit for Micronaut (Nimbus JOSE+JWT) — CVE-2023-52428
vendor_oracle·2025-01-15·CVSS 7.5
CVE-2023-52428 [HIGH] Oracle Oracle Database Server Risk Matrix: Oracle Graal Development Kit for Micronaut (Nimbus JOSE+JWT) — CVE-2023-52428
Oracle Oracle Database Server Risk Matrix: Oracle Graal Development Kit for Micronaut (Nimbus JOSE+JWT) vulnerability
CVE: CVE-2023-52428
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
Atlassian
CVE-2023-52428: DoS (Denial of Service) com.nimbusds:nimbus-jose-jwt Dependency in Jira Service Management Data Center and Server
vendor_atlassian·2024-11-19·CVSS 7.5
CVE-2023-52428 [HIGH] CVE-2023-52428: DoS (Denial of Service) com.nimbusds:nimbus-jose-jwt Dependency in Jira Service Management Data Center and Server
CVE-2023-52428: DoS (Denial of Service) com.nimbusds:nimbus-jose-jwt Dependency in Jira Service Management Data Center and Server
DoS (Denial of Service) com.nimbusds:nimbus-jose-jwt Dependency in Jira Service Management Data Center and Server
CVE: CVE-2023-52428
Affected products: Jira Service Management
Oracle
Oracle Oracle Analytics Risk Matrix: Storage Service Integration (Nimbus JOSE+JWT) — CVE-2023-52428
vendor_oracle·2024-07-15·CVSS 7.5
CVE-2023-52428 [HIGH] Oracle Oracle Analytics Risk Matrix: Storage Service Integration (Nimbus JOSE+JWT) — CVE-2023-52428
Oracle Oracle Analytics Risk Matrix: Storage Service Integration (Nimbus JOSE+JWT) vulnerability
CVE: CVE-2023-52428
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Integration (Nimbus JOSE+JWT) — CVE-2023-52428
vendor_oracle·2024-04-15·CVSS 7.5
CVE-2023-52428 [HIGH] Oracle Oracle Construction and Engineering Risk Matrix: Integration (Nimbus JOSE+JWT) — CVE-2023-52428
Oracle Oracle Construction and Engineering Risk Matrix: Integration (Nimbus JOSE+JWT) vulnerability
CVE: CVE-2023-52428
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Red Hat
nimbus-jose-jwt: large JWE p2c header value causes Denial of Service
vendor_redhat·2024-02-11·CVSS 7.5
CVE-2023-52428 [HIGH] CWE-400 nimbus-jose-jwt: large JWE p2c header value causes Denial of Service
nimbus-jose-jwt: large JWE p2c header value causes Denial of Service
In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.
A vulnerability was found in the Nimbus Jose JWT package. By crafting a JWE with an excessively large p2c value, an attacker can trigger significant resource consumption during decryption, potentially leading to application slowdown or unavailability.
Package: com.nimbusds/nimbus-jose-jwt (Cryostat 3) - Not affected
Package: com.nimbusds/nimbus-jose-jwt (Logging Subsystem for Red Hat OpenShift) - Affected
Package: com.nimbusds/nimbus-jose-jwt (Red Hat AMQ Broker 7) - Will not fix
Package: com.nimbusds/ni
GHSA
Denial of Service in Connect2id Nimbus JOSE+JWT
ghsa·2024-02-11
CVE-2023-52428 [HIGH] CWE-400 Denial of Service in Connect2id Nimbus JOSE+JWT
Denial of Service in Connect2id Nimbus JOSE+JWT
In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.
OSV
Denial of Service in Connect2id Nimbus JOSE+JWT
osv·2024-02-11
CVE-2023-52428 [HIGH] Denial of Service in Connect2id Nimbus JOSE+JWT
Denial of Service in Connect2id Nimbus JOSE+JWT
In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.
No detection rules found.
No public exploits indexed.
https://bitbucket.org/connect2id/nimbus-jose-jwt/commits/3b3b77ehttps://bitbucket.org/connect2id/nimbus-jose-jwt/issues/526/https://connect2id.com/products/nimbus-jose-jwthttps://bitbucket.org/connect2id/nimbus-jose-jwt/commits/3b3b77ehttps://bitbucket.org/connect2id/nimbus-jose-jwt/issues/526/https://connect2id.com/products/nimbus-jose-jwt
2024-02-11
Published