The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
{ "binaries": [ { "binary_name": "libjose4j-java", "binary_version": "0.7.7-2" } ] }
{ "binaries": [ { "binary_name": "libjose4j-java", "binary_version": "0.7.12-2" } ] }
{ "binaries": [ { "binary_name": "libjose4j-java", "binary_version": "0.9.6-1" } ] }