[ https://issues.apache.org/jira/browse/HADOOP-19687?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
ASF GitHub Bot updated HADOOP-19687: ------------------------------------ Labels: pull-request-available (was: ) > Upgrade nimbus-jose-jwt to 10.0.2+ due to CVE-2025-53864 > -------------------------------------------------------- > > Key: HADOOP-19687 > URL: https://issues.apache.org/jira/browse/HADOOP-19687 > Project: Hadoop Common > Issue Type: Task > Reporter: Rohit Kumar > Priority: Major > Labels: pull-request-available > > *CVE-2025-53864:* > Connect2id Nimbus JOSE + JWT before 10.0.2 allows a remote attacker to cause > a denial of service via a deeply nested JSON object supplied in a JWT claim > set, because of uncontrolled recursion. NOTE: this is independent of the Gson > 2.11.0 issue because the Connect2id product could have checked the JSON > object nesting depth, regardless of what limits (if any) were imposed by Gson. > Severity: 6.9 (medium) -- This message was sent by Atlassian Jira (v8.20.10#820010) --------------------------------------------------------------------- To unsubscribe, e-mail: common-issues-unsubscr...@hadoop.apache.org For additional commands, e-mail: common-issues-h...@hadoop.apache.org