REDHAT-BUG-2270538: Medium severity latchset jose vulnerability
latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
https://github.com/P3ngu1nW/CVERequest/blob/main/latch-jose.md https://github.com/latchset/jose
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
latchset/joseto a version that resolves this vulnerability.Fixed in 11
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2270538?
The severity of REDHAT-BUG-2270538 is categorized as a denial of service vulnerability.
How does REDHAT-BUG-2270538 affect Latchset Jose?
REDHAT-BUG-2270538 allows attackers to cause high CPU consumption in Latchset Jose through a large PBES2 Count value.
What versions of Latchset Jose are vulnerable to REDHAT-BUG-2270538?
Latchset Jose versions up to and including version 11 are affected by REDHAT-BUG-2270538.
How can I mitigate the risks associated with REDHAT-BUG-2270538?
To mitigate the risks of REDHAT-BUG-2270538, you should upgrade to a patched version of Latchset Jose that addresses this vulnerability.
Is there any known exploit for REDHAT-BUG-2270538?
There is currently no publicly available exploit for REDHAT-BUG-2270538, but it poses a risk of denial of service.