CVE-2023-52428: High severity Connect2id Nimbus Jose\+jwt vulnerability
Connect2id Nimbus-JOSE-JWT is vulnerable to a denial of service, caused by improper validation of user requests by the PasswordBasedDecrypter (PBKDF2) component. By sending a specially crafted request using a large JWE p2c header, a remote attacker could exploit this vulnerability to cause a denial of service.
Other sources
In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52428?
CVE-2023-52428 has been assessed to pose a moderate severity risk due to its potential for denial of service.
How do I fix CVE-2023-52428?
To fix CVE-2023-52428, users should upgrade to version 9.37.2 or later of the com.nimbusds:nimbus-jose-jwt package.
What components are affected by CVE-2023-52428?
CVE-2023-52428 affects the PasswordBasedDecrypter (PBKDF2) component within the Connect2id Nimbus-JOSE-JWT library.
Can CVE-2023-52428 be exploited remotely?
Yes, CVE-2023-52428 can be exploited remotely by sending specially crafted requests with a large JWE p2c header.
Which software should be monitored for CVE-2023-52428?
Software such as Connect2id Nimbus JOSE+JWT and IBM Planning Analytics versions 2.0 and 2.1 should be monitored for CVE-2023-52428.