CVE Vulnerabilities

CVE-2023-51775

Uncontrolled Resource Consumption

Published: Feb 29, 2024 | Modified: May 08, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

Weakness

The product does not properly control the allocation and maintenance of a limited resource.

Affected Software

Name Vendor Start Version End Version
Jose4j Jose4j_project * 0.9.4 (excluding)
HawtIO 4.0.0 for Red Hat build of Apache Camel 4 RedHat jose4j *
Important: Red Hat JBoss Enterprise Application Platform 7.4.19 Security update RedHat jose4j *
Red Hat build of Apicurio Registry 2.6.1 GA RedHat jose4j *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-hal-console-0:3.3.24-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-hibernate-validator-0:6.0.23-2.SP1_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-insights-java-client-0:1.1.3-1.redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-ironjacamar-0:1.5.18-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-jboss-cert-helper-0:1.1.3-1.redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-jboss-ejb-client-0:4.0.55-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-jboss-server-migration-0:1.10.0-39.Final_redhat_00039.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-jbossws-cxf-0:5.4.12-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-jsoup-0:1.15.4-1.redhat_00003.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-undertow-jastow-0:2.0.15-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-wildfly-0:7.4.19-1.GA_redhat_00002.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-xalan-j2-0:2.7.1-37.redhat_00015.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-hal-console-0:3.3.24-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-hibernate-validator-0:6.0.23-2.SP1_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-insights-java-client-0:1.1.3-1.redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-ironjacamar-0:1.5.18-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-jboss-cert-helper-0:1.1.3-1.redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-jboss-ejb-client-0:4.0.55-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-jboss-server-migration-0:1.10.0-39.Final_redhat_00039.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-jbossws-cxf-0:5.4.12-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-jsoup-0:1.15.4-1.redhat_00003.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-undertow-jastow-0:2.0.15-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-wildfly-0:7.4.19-1.GA_redhat_00002.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-xalan-j2-0:2.7.1-37.redhat_00015.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-hal-console-0:3.3.24-1.Final_redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-hibernate-validator-0:6.0.23-2.SP1_redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-insights-java-client-0:1.1.3-1.redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-ironjacamar-0:1.5.18-1.Final_redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-jboss-cert-helper-0:1.1.3-1.redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-jboss-ejb-client-0:4.0.55-1.Final_redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-jboss-server-migration-0:1.10.0-39.Final_redhat_00039.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-jbossws-cxf-0:5.4.12-1.Final_redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-jsoup-0:1.15.4-1.redhat_00003.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-undertow-jastow-0:2.0.15-1.Final_redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-wildfly-0:7.4.19-1.GA_redhat_00002.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-xalan-j2-0:2.7.1-37.redhat_00015.1.el7eap *
Red Hat JBoss Enterprise Application Platform 8 RedHat jose4j *
Red Hat JBoss Enterprise Application Platform Expansion Pack RedHat *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-data-index-ephemeral-rhel8:1.33.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-data-index-postgresql-rhel8:1.33.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-jobs-service-ephemeral-rhel8:1.33.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-jobs-service-postgresql-rhel8:1.33.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8:1.33.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-operator-bundle:1.33.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-rhel8-operator:1.33.0-3 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-swf-builder-rhel8:1.33.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-swf-devmode-rhel8:1.33.0-5 *
Libjose4j-java Ubuntu bionic *
Libjose4j-java Ubuntu lunar *
Libjose4j-java Ubuntu mantic *
Libjose4j-java Ubuntu oracular *
Libjose4j-java Ubuntu trusty *
Libjose4j-java Ubuntu xenial *

Potential Mitigations

  • Mitigation of resource exhaustion attacks requires that the target system either:

  • The first of these solutions is an issue in itself though, since it may allow attackers to prevent the use of the system by a particular valid user. If the attacker impersonates the valid user, they may be able to prevent the user from accessing the server in question.

  • The second solution is simply difficult to effectively institute – and even when properly done, it does not provide a full solution. It simply makes the attack require more resources on the part of the attacker.

References