jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2687 | jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less. |
Github GHSA |
GHSA-7g24-qg88-p43q | jose4j uses weak cryptographic algorithm |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-11T18:37:34.066Z
Reserved: 2023-04-29T00:00:00
Link: CVE-2023-31582
Updated: 2024-08-02T14:53:30.902Z
Status : Modified
Published: 2023-10-25T18:17:27.777
Modified: 2024-11-21T08:02:03.167
Link: CVE-2023-31582
OpenCVE Enrichment
No data.
EUVD
Github GHSA