You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
ADAL is using very old nimbusVersion 9.9 which has a vulnerability (CVE-2023-52428) CVE-2023-52428 Denial of Service in Connect2id Nimbus JOSE+JWT In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.
Can you help us with the impact assessment of this vulnerability?
The text was updated successfully, but these errors were encountered:
asthagarg2428
changed the title
CVE-2023-52428 in com.nimbusds:nimbus-jose-jwt
[Impact Assessment] CVE-2023-52428 in com.nimbusds:nimbus-jose-jwt
Oct 22, 2024
ADAL is using very old nimbusVersion 9.9 which has a vulnerability (CVE-2023-52428)
CVE-2023-52428 Denial of Service in Connect2id Nimbus JOSE+JWT In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.
Can you help us with the impact assessment of this vulnerability?
The text was updated successfully, but these errors were encountered: