The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
{ "binaries": [ { "binary_version": "0.7.7-2", "binary_name": "libjose4j-java" } ] }
{ "binaries": [ { "binary_version": "0.7.12-2", "binary_name": "libjose4j-java" } ] }
{ "binaries": [ { "binary_version": "0.9.6-1", "binary_name": "libjose4j-java" } ] }