CVE-2024-29371
jose4j is vulnerable to DoS via compressed JWE content
7.5
HIGH
CVSS 3.1
EPSS 0.24%
Description
In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.
How to fix CVE-2024-29371
To remediate CVE-2024-29371, upgrade the affected package to a fixed version below.
- —upgrade to 0.9.6-1 or later
- —upgrade to 0.9.6 or later
Is CVE-2024-29371 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.9.6-1
- from 0, < 0.9.6
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |