Back

MEDIUM

Jwcrypto: denail of service via specifically crafted jwe

Published Feb 12, 2024

Description

A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more resource-intensive. This issue can result in a large amount of computational consumption, causing a denial of service attack.

Affected products

Remediation

Vendor solution

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Red Hat statement

The identified vulnerability within the jwcrypto package, presents a moderate severity concern rather than a important one due to several mitigating factors. While the unbounded PBES2 Count value in PBKDF2 algorithms can potentially facilitate a Denial of Service (DoS) attack, its severity is tempered by the fact that successful exploitation requires specific conditions and considerable computational resources. Additionally, applications not reliant on PBKDF2 can easily exclude it from their algorithms list, further reducing exposure.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 12, 2024
Updated Feb 26, 2026
Reserved Dec 11, 2023
CISA Vulnrichment
Updated Feb 12, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 28, 2023
GHSA-CW2R-4P82-QV79