CVE-2023-51775: Input Validation
jose4j is vulnerable to a denial of service, caused by improper input validation. By sending a specially crafted p2c value, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Other sources
The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51775?
CVE-2023-51775 is classified as a denial of service vulnerability due to improper input validation.
How do I fix CVE-2023-51775?
To fix CVE-2023-51775, upgrade the jose4j library to version 0.9.4 or later.
Which versions of jose4j are affected by CVE-2023-51775?
Versions of jose4j prior to 0.9.4 are affected by CVE-2023-51775.
Can CVE-2023-51775 affect IBM Security Verify Governance?
Yes, CVE-2023-51775 can affect IBM Security Verify Governance versions up to ISVG 10.0.2.
What type of attack can exploit CVE-2023-51775?
CVE-2023-51775 can be exploited by attackers using a specially crafted p2c value, leading to a denial of service condition.