CVE-2023-50658 is a denial-of-service vulnerability affecting the dvsekhvalnov jose2go component prior to version 1.6.0. An unauthenticated attacker can exploit this by providing a large p2c (PBES2 Count) value, leading to high CPU consumption and service disruption. With a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with low attack complexity, resulting in a high impact on availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.0CPE matchmatch criteria | cpe:2.3:a:dvsekhvalnov:jose2go:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk Enterprise - October 2024
Oct 14, 2024jose2go vulnerable to denial of service via large p2c value
Feb 29, 2024The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
Dec 12, 2023