Jwcrypto: denail of service via specifically crafted jwe
Published Feb 12, 2024
5.3
MEDIUMCVSS 3.1
EPSS 0.88%
Description
A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more resource-intensive. This issue can result in a large amount of computational consumption, causing a denial of service attack.
Affected products
No data.
Configuration 2
- 38
- 39
- 8.0
- 9.0
- 8.0
- 8.0
- 8.0
No data.
Red Hat Enterprise Linux 8
idm:DL1-8100020240416171943.823393f5
Fixed · RHSA-2024:3267
Red Hat Enterprise Linux 8
idm:client-8100020240417004735.143e9e98
Fixed · RHSA-2024:3267
Red Hat Enterprise Linux 9
python-jwcrypto-0:1.5.6-2.el9
Fixed · RHSA-2024:9281
Red Hat Ansible Automation Platform 2
automation-controller
Not affected
Red Hat Enterprise Linux 7
python-jwcrypto
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | idm:DL1-8100020240416171943.823393f5 | Fixed | RHSA-2024:3267 |
| Red Hat Enterprise Linux 8 | idm:client-8100020240417004735.143e9e98 | Fixed | RHSA-2024:3267 |
| Red Hat Enterprise Linux 9 | python-jwcrypto-0:1.5.6-2.el9 | Fixed | RHSA-2024:9281 |
| Red Hat Ansible Automation Platform 2 | automation-controller | Not affected | n/a |
| Red Hat Enterprise Linux 7 | python-jwcrypto | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
The identified vulnerability within the jwcrypto package, presents a moderate severity concern rather than a important one due to several mitigating factors. While the unbounded PBES2 Count value in PBKDF2 algorithms can potentially facilitate a Denial of Service (DoS) attack, its severity is tempered by the fact that successful exploitation requires specific conditions and considerable computational resources. Additionally, applications not reliant on PBKDF2 can easily exclude it from their algorithms list, further reducing exposure.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Feb 12, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (6 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.88% (0.00884) | 57.73th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.88% (0.00884) | 54.33th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.42% (0.00423) | 60.00th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00052) | 22.12th | v3 (v2023.03.01) |
| May 23, 2024 | 0.04% (0.00045) | 15.04th | v3 (v2023.03.01) |
| Feb 13, 2024 | 0.04% (0.00043) | 6.69th | v3 (v2023.03.01) |
References (10)
- https://access.redhat.com/errata/RHSA-2024:3267 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:9281 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-6681 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2260843 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://github.com/advisories/GHSA-cw2r-4p82-qv79 Advisory
- https://github.com/latchset/jwcrypto/commit/d2655d370586cb830e49acfb450f87598da60be8
- https://github.com/latchset/jwcrypto/security/advisories/GHSA-cw2r-4p82-qv79
- https://github.com/pypa/advisory-database/tree/main/vulns/jwcrypto/PYSEC-2024-104.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2023-6681
- https://www.cve.org/CVERecord?id=CVE-2023-6681
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2024:3267 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2024:9281 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2023-6681 | vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2260843 | issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory | |
| https://github.com/advisories/GHSA-cw2r-4p82-qv79 | Advisory | |
| https://github.com/latchset/jwcrypto/commit/d2655d370586cb830e49acfb450f87598da60be8 | ||
| https://github.com/latchset/jwcrypto/security/advisories/GHSA-cw2r-4p82-qv79 | ||
| https://github.com/pypa/advisory-database/tree/main/vulns/jwcrypto/PYSEC-2024-104.yaml | ||
| https://nvd.nist.gov/vuln/detail/CVE-2023-6681 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-6681 |
Change history (0)
No recorded changes yet.