Description
A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more resource-intensive. This issue can result in a large amount of computational consumption, causing a denial of service attack.
Published: 2024-02-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-0081 A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more resource-intensive. This issue can result in a large amount of computational consumption, causing a denial of service attack.
Github GHSA Github GHSA GHSA-cw2r-4p82-qv79 DoS with algorithms that use PBKDF2 due to unbounded PBES2 Count value
History

Wed, 13 Nov 2024 02:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:9

Tue, 12 Nov 2024 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:9 cpe:/a:redhat:enterprise_linux:9::appstream
References

Thu, 10 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Oct 2024 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Fedoraproject
Fedoraproject fedora
Latchset
Latchset jwcrypto
Redhat enterprise Linux For Arm 64
Redhat enterprise Linux For Ibm Z Systems
Redhat enterprise Linux For Power Little Endian
CPEs cpe:2.3:a:latchset:jwcrypto:*:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_arm_64:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0:*:*:*:*:*:*:*
Vendors & Products Fedoraproject
Fedoraproject fedora
Latchset
Latchset jwcrypto
Redhat enterprise Linux For Arm 64
Redhat enterprise Linux For Ibm Z Systems
Redhat enterprise Linux For Power Little Endian

Subscriptions

Fedoraproject Fedora
Latchset Jwcrypto
Redhat Ansible Automation Platform Enterprise Linux Enterprise Linux For Arm 64 Enterprise Linux For Ibm Z Systems Enterprise Linux For Power Little Endian
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-02-26T20:34:50.814Z

Reserved: 2023-12-11T12:45:07.051Z

Link: CVE-2023-6681

cve-icon Vulnrichment

Updated: 2024-08-02T08:35:14.893Z

cve-icon NVD

Status : Modified

Published: 2024-02-12T14:15:08.003

Modified: 2024-11-21T08:44:20.090

Link: CVE-2023-6681

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-12-28T00:00:00Z

Links: CVE-2023-6681 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses