CVE-2023-52428
HighAdvisory
Published 11 Feb 2024In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.008
- 55th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 128
- of 17,781 indexed, latest versions
- Container images
- 137
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Denial of Service in Connect2id Nimbus JOSE+JWT
Carried by container images the latest versions of 128 of 17,781 indexed charts deploy, on 137 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| nimbus-jose-jwtmaven | 3.1.2, 3.9, 4.41.1, 4.41.2+29 more | 9.37.2 | 137 |
- OSV records
- GHSA-gvpg-vgmx-xg6w
Charts affected
128 by stars
Container images carrying it
137 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | 52f376e64b9b | nimbus-jose-jwt | 9.37.2 | 4 |
| apache/ | 0bd3b25c4be4 | nimbus-jose-jwt | 9.37.2 | 3 |
| gchq/ | 5ec58edbb2db | nimbus-jose-jwt | 9.37.2 | 3 |
| mockserver/ | 0f9ef78c9489 | nimbus-jose-jwt | 9.37.2 | 3 |
| provectuslabs/ | 8f2ff02d64b0 | nimbus-jose-jwt | 9.37.2 | 3 |
| apache/ | 0116fb802786 | nimbus-jose-jwt | 9.37.2 | 2 |
| danisla/ | 255ba2dd739b | nimbus-jose-jwt | 9.37.2 | 2 |
| dependencytrack/ | 485ac0952c02 | nimbus-jose-jwt | 9.37.2 | 2 |
| hookiesolutions/ | 0629694246ba | nimbus-jose-jwt | 9.37.2 | 2 |
| inaccel/ | 8c53744ed70b | nimbus-jose-jwt | 9.37.2 | 2 |
| library/ | 5e6ac15bf6a5 | nimbus-jose-jwt | 9.37.2 | 2 |
| scorpiobroker/ | 01e11d800459 | nimbus-jose-jwt | 9.37.2 | 2 |
| scorpiobroker/ | 3f05a113a4be | nimbus-jose-jwt | 9.37.2 | 2 |
| scorpiobroker/ | 5073ceef2fa0 | nimbus-jose-jwt | 9.37.2 | 2 |
| scorpiobroker/ | 62dae3dd0eeb | nimbus-jose-jwt | 9.37.2 | 2 |
| scorpiobroker/ | a2cfcf0947fd | nimbus-jose-jwt | 9.37.2 | 2 |
| scorpiobroker/ | b742a53b2803 | nimbus-jose-jwt | 9.37.2 | 2 |
| scorpiobroker/ | b7fe27a06ff5 | nimbus-jose-jwt | 9.37.2 | 2 |
| scorpiobroker/ | e08036670d66 | nimbus-jose-jwt | 9.37.2 | 2 |
| scorpiobroker/ | f02e8a429a08 | nimbus-jose-jwt | 9.37.2 | 2 |
| quay.io/ | 02f6f143fc6d | nimbus-jose-jwt | 9.37.2 | 2 |
| 5200710/ | 092d3088a5fb | nimbus-jose-jwt | 9.37.2 | 1 |
| 5200710/ | e34ab066d2ed | nimbus-jose-jwt | 9.37.2 | 1 |
| adityaprasadpathak/ | 7e3b9777362c | nimbus-jose-jwt | 9.37.2 | 1 |
| aktosecurity/ | bcd7382c9c1b | nimbus-jose-jwt | 9.37.2 | 1 |
| aktosecurity/ | 274042ed7a53 | nimbus-jose-jwt | 9.37.2 | 1 |
| apache/ | 1f96558fd292 | nimbus-jose-jwt | 9.37.2 | 1 |
| apache/ | 0cef139b6bf1 | nimbus-jose-jwt | 9.37.2 | 1 |
| apache/ | 80136ae753ee | nimbus-jose-jwt | 9.37.2 | 1 |
| apache/ | af361b20bec0 | nimbus-jose-jwt | 9.37.2 | 1 |
| apache/ | 8647309f95d1 | nimbus-jose-jwt | 9.37.2 | 1 |
| apache/ | afa47bf1692a | nimbus-jose-jwt | 9.37.2 | 1 |
| apache/ | 090b7f87ec7f | nimbus-jose-jwt | 9.37.2 | 1 |
| apache/ | 974efa2f21da | nimbus-jose-jwt | 9.37.2 | 1 |
| apache/ | 76c176e8a0e4 | nimbus-jose-jwt | 9.37.2 | 1 |
| apache/ | 1bd5756f6273 | nimbus-jose-jwt | 9.37.2 | 1 |
| assistiot/ | 4228b7a8ef40 | nimbus-jose-jwt | 9.37.2 | 1 |
| assistiot/ | c8b6c7eaa0cd | nimbus-jose-jwt | 9.37.2 | 1 |
| atlassian/ | 3b9222ab32ef | nimbus-jose-jwt | 9.37.2 | 1 |
| atlassian/ | ebf761c7d437 | nimbus-jose-jwt | 9.37.2 | 1 |
| atlassian/ | 37bc46cbec1a | nimbus-jose-jwt | 9.37.2 | 1 |
| atlassian/ | 64a75aa4ec4e | nimbus-jose-jwt | 9.37.2 | 1 |
| bitnamilegacy/ | 15d4647fd491 | nimbus-jose-jwt | 9.37.2 | 1 |
| bitnamilegacy/ | 9cfd2df1294d | nimbus-jose-jwt | 9.37.2 | 1 |
| bivas/ | 05545994f806 | nimbus-jose-jwt | 9.37.2 | 1 |
| ckan/ | ef8e5d3e6be1 | nimbus-jose-jwt | 9.37.2 | 1 |
| confluentinc/ | f2975d507a2a | nimbus-jose-jwt | 9.37.2 | 1 |
| confluentinc/ | 8f1544df1f48 | nimbus-jose-jwt | 9.37.2 | 1 |
| confluentinc/ | 4bc70a83ca6f | nimbus-jose-jwt | 9.37.2 | 1 |
| confluentinc/ | b0b7aa26254a | nimbus-jose-jwt | 9.37.2 | 1 |