Improper resource allocation In jose-node-cjs-runtime
Description
Jose was found to have an uncontrolled resource consumption vulnerability. Under certain conditions, the user's environment can consume an unreasonable amount of CPU time or memory during JWE decryption operations, leading to a denial of service.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
npm | 4.15.5 | ||
npm | 4.15.5 | ||
npm | 4.15.5, 2.0.7 | ||
rpm rhel9 | 0:14-1.el9 | ||
rpm rhel9 | 4:4.9.4-4.el9_4 | ||
rpm rhel8 | 0:10-2.el8_10.3 | ||
rpm rhel7 | - | - | |
rpm rhel9 | 2:1.33.7-2.el9_4 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4. 5. 6. 7. 8.