exasol / kafka-connector-extension

Exasol Kafka Extension for accessing Apache Kafka
MIT License
4 stars 7 forks source link

🔐 CVE-2023-51775: org.bitbucket.b_c:jose4j:jar:0.9.3:test #90

Closed github-actions[bot] closed 6 months ago

github-actions[bot] commented 6 months ago

Summary

The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

Sonatype's research suggests that this CVE's details differ from those defined at NVD. See https://ossindex.sonatype.org/vulnerability/CVE-2023-51775 for details

CVE: CVE-2023-51775 CWE: CWE-400

References