jose4j
cpe:2.3:a:jose4j_project:jose4j:*:*:*:*:*:*:*
- < 0.9.5
A denial-of-service vulnerability has been identified in jose4j versions prior to 0.9.5. The issue arises when an attacker crafts a JSON Web Encryption (JWE) token with a very high compression ratio. When the server processes this token, it leads to excessive memory usage and prolonged processing times during decompression, causing a denial-of-service condition.
Exploitation of this vulnerability leads to a denial-of-service condition, causing significant memory consumption and increased processing times on the server.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.