jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less.
{ "binaries": [ { "binary_version": "0.7.7-2", "binary_name": "libjose4j-java" } ] }
{ "binaries": [ { "binary_version": "0.7.12-2", "binary_name": "libjose4j-java" } ] }
{ "binaries": [ { "binary_version": "0.9.6-1", "binary_name": "libjose4j-java" } ] }