CVE-2023-50658

The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dvsekhvalnov:jose2go:*:*:*:*:*:go:*:*

History

14 Feb 2025, 17:23

Type Values Removed Values Added
References () https://github.com/dvsekhvalnov/jose2go/commit/a4584e9dd7128608fedbc67892eba9697f0d5317 - () https://github.com/dvsekhvalnov/jose2go/commit/a4584e9dd7128608fedbc67892eba9697f0d5317 - Patch
References () https://github.com/dvsekhvalnov/jose2go/compare/v1.5.0...v1.6.0 - () https://github.com/dvsekhvalnov/jose2go/compare/v1.5.0...v1.6.0 - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:dvsekhvalnov:jose2go:*:*:*:*:*:go:*:*
First Time Dvsekhvalnov jose2go
Dvsekhvalnov
CWE CWE-770

21 Nov 2024, 08:37

Type Values Removed Values Added
Summary
  • (es) El componente jose2go anterior a 1.6.0 para Go permite a los atacantes provocar una denegación de servicio (consumo de CPU) a través de un valor grande de p2c (también conocido como PBES2 Count).
References () https://github.com/dvsekhvalnov/jose2go/commit/a4584e9dd7128608fedbc67892eba9697f0d5317 - () https://github.com/dvsekhvalnov/jose2go/commit/a4584e9dd7128608fedbc67892eba9697f0d5317 -
References () https://github.com/dvsekhvalnov/jose2go/compare/v1.5.0...v1.6.0 - () https://github.com/dvsekhvalnov/jose2go/compare/v1.5.0...v1.6.0 -

29 Feb 2024, 01:42

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-29 01:42

Updated : 2025-02-14 17:23


NVD link : CVE-2023-50658

Mitre link : CVE-2023-50658

CVE.ORG link : CVE-2023-50658


JSON object : View

Products Affected

dvsekhvalnov

  • jose2go
CWE
CWE-770

Allocation of Resources Without Limits or Throttling