CVE-2023-31582: jose4j uses weak cryptographic algorithm
(updated )
jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less.
References
Detect and mitigate CVE-2023-31582 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →