In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.nimbusds:nimbus-jose-jwt(Maven) | 0 | 9.37.2 | N/A |
CVSS Metrics