Authors: Created by IBM


There is a vulnerability in the jose4j library used by IBM WebSphere Application Server traditional and WebSphere Application Server Liberty. CVEID:  CVE-2024-29371[1]
DESCRIPTION:  In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio.When this token is processed by the server, it results in significant memory allocation and processing...

Just published by IBM: Read more