-
Bug
-
Resolution: Done-Errata
-
Undefined
-
None
-
None
-
None
-
False
-
None
-
False
-
-
In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.
- links to
-
RHSA-2024:132366 Red Hat AMQ Streams 2.7.0 release and security update
-
RHSA-2024:138376 Red Hat AMQ Streams 2.5.2 release and security update