Description
jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less.
Remediation
References
https://bitbucket.org/b_c/jose4j/issues/203/insecure-support-of-setting-pbe-less-then
https://github.com/KANIXB/JWTIssues/blob/main/jose4j%20issue.md
Related Vulnerabilities
CVE-2020-28246 Vulnerability in maven package org.webjars.npm:formio
CVE-2020-13959 Vulnerability in maven package org.apache.velocity.tools:velocity-tools-view
CVE-2022-39203 Vulnerability in npm package matrix-appservice-irc
CVE-2021-23341 Vulnerability in npm package prismjs
CVE-2019-10333 Vulnerability in maven package org.jenkins-ci.plugins:electricflow