This advisory has been withdrawn because it is a duplicate of GHSA-6294-6rgp-fr7r. This link is maintained to preserve external references.
An attacker controlled input of a PBES2 encrypted JWE blob can have a very large p2c value that, when decrypted, produces a denial-of-service.
{
"github_reviewed_at": "2023-12-20T20:31:57Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-400"
],
"github_reviewed": true,
"nvd_published_at": null
}