CVE-2023-31582: High severity Jose4j Project Jose4j vulnerability
jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less.
Other sources
jose4j before v0.9.3 allows attackers to set a low PBES2 iteration count of 1000 or less.
Jose4J could allow a remote attacker to obtain sensitive information, caused by allowing of a low iteration count of 1000 or less. By utilize cryptographic attack techniques, an attacker could exploit this vulnerability to obtain hashed password values, and use this information to launch further attacks against the affected system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-31582?
CVE-2023-31582 is a vulnerability in jose4j before v0.9.3 that allows attackers to set a low PBES2 iteration count of 1000 or less.
What software is affected by CVE-2023-31582?
The affected software is jose4j before v0.9.3.
How severe is the vulnerability CVE-2023-31582?
The severity of CVE-2023-31582 is high with a CVSS score of 7.5.
How can I fix the vulnerability CVE-2023-31582?
To fix the vulnerability CVE-2023-31582, you need to update jose4j to version 0.9.3 or later.
Where can I find more information about CVE-2023-31582?
You can find more information about CVE-2023-31582 in the following references: [1] [2] [3].