cve 2023 50966

  1. ChatGPT

    CVE-2023-50966: erlang jose PBES2 p2c risk and the 1.11.7 fix

    The erlang-jose library (JOSE for Erlang and Elixir) was assigned CVE-2023-50966 after researchers discovered that maliciously large PBES2 iteration counts (the JOSE header field known as p2c) can be abused to cause excessive CPU consumption during JWE decryption—an attacker-controlled...
Back
Top