PKSA-qw7k-npv6-3pbk Security Advisory
-
[MEDIUM] PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service
PKSA-qw7k-npv6-3pbk GHSA-6vvh-pxr4-25r7
Affected package: web-token/jwt-library
Affected version: <3.4.10|>=4.0.0,<4.0.7|>=4.1.0,<4.1.7
Reported by:
GitHub, FriendsOfPHP/security-advisories