CVE Vulnerabilities

CVE-2023-51775

Uncontrolled Resource Consumption

Published: Feb 29, 2024 | Modified: Nov 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

Weakness

The product does not properly control the allocation and maintenance of a limited resource.

Affected Software

NameVendorStart VersionEnd Version
Jose4jJose4j_project*0.9.4 (excluding)
HawtIO 4.0.0 for Red Hat build of Apache Camel 4RedHatjose4j*
Red Hat build of Apicurio Registry 2.6.1 GARedHatjose4j*
Red Hat JBoss Enterprise Application Platform 7RedHatjose4j*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-hal-console-0:3.3.24-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-hibernate-validator-0:6.0.23-2.SP1_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-insights-java-client-0:1.1.3-1.redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-ironjacamar-0:1.5.18-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-jboss-cert-helper-0:1.1.3-1.redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-jboss-ejb-client-0:4.0.55-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-jboss-server-migration-0:1.10.0-39.Final_redhat_00039.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-jbossws-cxf-0:5.4.12-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-jsoup-0:1.15.4-1.redhat_00003.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-undertow-jastow-0:2.0.15-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-wildfly-0:7.4.19-1.GA_redhat_00002.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-xalan-j2-0:2.7.1-37.redhat_00015.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-hal-console-0:3.3.24-1.Final_redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-hibernate-validator-0:6.0.23-2.SP1_redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-insights-java-client-0:1.1.3-1.redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-ironjacamar-0:1.5.18-1.Final_redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-jboss-cert-helper-0:1.1.3-1.redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-jboss-ejb-client-0:4.0.55-1.Final_redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-jboss-server-migration-0:1.10.0-39.Final_redhat_00039.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-jbossws-cxf-0:5.4.12-1.Final_redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-jsoup-0:1.15.4-1.redhat_00003.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-undertow-jastow-0:2.0.15-1.Final_redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-wildfly-0:7.4.19-1.GA_redhat_00002.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-xalan-j2-0:2.7.1-37.redhat_00015.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-hal-console-0:3.3.24-1.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-hibernate-validator-0:6.0.23-2.SP1_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-insights-java-client-0:1.1.3-1.redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-ironjacamar-0:1.5.18-1.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-jboss-cert-helper-0:1.1.3-1.redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-jboss-ejb-client-0:4.0.55-1.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-jboss-server-migration-0:1.10.0-39.Final_redhat_00039.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-jbossws-cxf-0:5.4.12-1.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-jsoup-0:1.15.4-1.redhat_00003.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-undertow-jastow-0:2.0.15-1.Final_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-wildfly-0:7.4.19-1.GA_redhat_00002.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-xalan-j2-0:2.7.1-37.redhat_00015.1.el7eap*
Red Hat JBoss Enterprise Application Platform 8RedHatjose4j*
Red Hat JBoss Enterprise Application Platform Expansion PackRedHat*
RHOSS-1.33-RHEL-8RedHatopenshift-serverless-1/logic-data-index-ephemeral-rhel8:1.33.0-5*
RHOSS-1.33-RHEL-8RedHatopenshift-serverless-1/logic-data-index-postgresql-rhel8:1.33.0-5*
RHOSS-1.33-RHEL-8RedHatopenshift-serverless-1/logic-jobs-service-ephemeral-rhel8:1.33.0-5*
RHOSS-1.33-RHEL-8RedHatopenshift-serverless-1/logic-jobs-service-postgresql-rhel8:1.33.0-5*
RHOSS-1.33-RHEL-8RedHatopenshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8:1.33.0-5*
RHOSS-1.33-RHEL-8RedHatopenshift-serverless-1/logic-operator-bundle:1.33.0-5*
RHOSS-1.33-RHEL-8RedHatopenshift-serverless-1/logic-rhel8-operator:1.33.0-3*
RHOSS-1.33-RHEL-8RedHatopenshift-serverless-1/logic-swf-builder-rhel8:1.33.0-5*
RHOSS-1.33-RHEL-8RedHatopenshift-serverless-1/logic-swf-devmode-rhel8:1.33.0-5*
Libjose4j-javaUbuntubionic*
Libjose4j-javaUbuntulunar*
Libjose4j-javaUbuntumantic*
Libjose4j-javaUbuntuoracular*
Libjose4j-javaUbuntuplucky*
Libjose4j-javaUbuntutrusty*
Libjose4j-javaUbuntuxenial*

Potential Mitigations

  • Mitigation of resource exhaustion attacks requires that the target system either:

  • The first of these solutions is an issue in itself though, since it may allow attackers to prevent the use of the system by a particular valid user. If the attacker impersonates the valid user, they may be able to prevent the user from accessing the server in question.

  • The second solution is simply difficult to effectively institute – and even when properly done, it does not provide a full solution. It simply makes the attack require more resources on the part of the attacker.

References