CVE-2024-29371: High severity maven/org.bitbucket.b_g/jose4j vulnerability
In jose4j before 0.9.5, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.
Other sources
In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.bitbucket.b_c:jose4jto a version that resolves this vulnerability.Fixed in 0.9.5
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29371?
CVE-2024-29371 is classified as a Denial-of-Service (DoS) vulnerability.
How do I fix CVE-2024-29371?
To fix CVE-2024-29371, upgrade jose4j to version 0.9.5 or later.
What type of attack is CVE-2024-29371 associated with?
CVE-2024-29371 is associated with a zip bomb attack that targets the processing of JWE tokens.
Which versions of jose4j are affected by CVE-2024-29371?
CVE-2024-29371 affects all versions of jose4j prior to 0.9.5.
What can happen if CVE-2024-29371 is exploited?
Exploiting CVE-2024-29371 can lead to significant memory allocation and processing time, causing a Denial-of-Service condition.