2024-05-25 21:48:12 +02:00
|
|
|
### [CVE-2023-51775](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-51775)
|
|
|
|

|
|
|
|

|
|
|
|

|
|
|
|
|
|
|
|
### Description
|
|
|
|
|
|
|
|
The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
|
|
|
|
|
|
|
|
### POC
|
|
|
|
|
|
|
|
#### Reference
|
|
|
|
- https://bitbucket.org/b_c/jose4j/issues/212
|
|
|
|
|
|
|
|
#### Github
|
2024-08-05 18:41:32 +00:00
|
|
|
- https://github.com/ytono/gcp-arcade
|
2024-05-25 21:48:12 +02:00
|
|
|
|