CVE-2023-51775
Aliases:GHSA-6qvw-249j-h44cDEBIAN-CVE-2023-51775CGA-5c4f-r8hv-r6j3CGA-6mvv-2g46-5j3cCGA-cgw9-5f9w-v56jCGA-hxgh-jvpv-6mf5CGA-mmc8-cgg5-x52mCGA-qqr4-7jx2-q7vh
Advisory lineage Upstream: 0 Downstream: 7
Modified
Published: 25 Dec 2023, 00:00
Last modified:03 Nov 2025, 21:50
Vulnerability Summary
Overall Risk (default)
medium
36/100 CVSS Score
6.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.87% LOW
1% probability +0.44%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected
Timeline
25 Dec 2023, 00:00
Published
Vulnerability first disclosed
03 Nov 2025, 21:50
Last Modified
Vulnerability information updated
Description
The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
CVSS Metrics
- v3.1•MEDIUM•Score: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.87%• Percentile: 57%
Techniques & Countermeasures
- CWE-400•Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
Affected Systems
- chainguard•confluent-common-docker
< 7.6.9-r0
- chainguard•confluent-kafka
< 8.2.0.367-r0
- chainguard•hadoop-fips-3.5
< 3.5.0-r4
- wolfi•confluent-common-docker
< 7.6.9-r0
- wolfi•confluent-kafka
< 8.2.0.367-r0
- debian•libjose4j-java
< 0.9.6-1 | < 0.9.6-1
- jose4j_project•jose4j
< 0.9.4
- org.bitbucket.b_c•jose4j
< 0.9.4
References (6)
- https://bitbucket.org/b_c/jose4j/issues/212
- https://security.netapp.com/advisory/ntap-20241108-0002/
- https://nvd.nist.gov/vuln/detail/CVE-2023-51775
- https://bitbucket.org/b_c/jose4j/commits/1afaa1e174b3
- https://security.netapp.com/advisory/ntap-20241108-0002
- https://security-tracker.debian.org/tracker/CVE-2023-51775