Description
jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less.
Remediation
References
https://bitbucket.org/b_c/jose4j/issues/203/insecure-support-of-setting-pbe-less-then
https://github.com/KANIXB/JWTIssues/blob/main/jose4j%20issue.md
Related Vulnerabilities
CVE-2022-46366 Vulnerability in maven package tapestry:tapestry
CVE-2021-42767 Vulnerability in maven package org.neo4j.procedure:apoc
CVE-2023-47322 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web
CVE-2021-23463 Vulnerability in maven package com.h2database:h2
CVE-2023-29923 Vulnerability in maven package tech.powerjob:powerjob