CVE-2023-50966 Information
Mar 20, 2024
cve
Description
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header.
Reference
https://github.com/potatosalad/erlang-jose https://hexdocs.pm/jose/JOSE.html https://github.com/P3ngu1nW/CVE_Request/blob/main/erlang-jose.md
Share on: