potatosalad/erlang-jose

potatosalad/erlang-jose

Releases46
Frequency2 months 3 weeks
Last Release
Stars334
JSON Object Signing and Encryption (JOSE) for Erlang and Elixir

CVE History

CVEPublishedCVSS v3CVSS v2
5.3 MEDIUM

erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header.