jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less.
{ "binaries": [ { "binary_name": "libjose4j-java", "binary_version": "0.7.7-2" } ] }
{ "binaries": [ { "binary_name": "libjose4j-java", "binary_version": "0.7.12-2" } ] }
{ "binaries": [ { "binary_name": "libjose4j-java", "binary_version": "0.9.6-1" } ] }