Connect2id Nimbus JOSE + JWT 4.40

CPE Details

Connect2id Nimbus JOSE + JWT 4.40
4.40
2020-01-29
12h52 +00:00
2020-01-29
12h52 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:connect2id:nimbus_jose\+jwt:4.40:*:*:*:*:*:*:*

Informations

Vendor

connect2id

Product

nimbus_jose\+jwt

Version

4.40

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-52428 2024-02-10 23h00 +00:00 In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.
7.5
High
CVE-2019-17195 2019-10-15 11h42 +00:00 Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
9.8
Critical