Medium severity5.3NVD Advisory· Published Feb 12, 2024· Updated Jun 17, 2026
CVE-2023-6681
CVE-2023-6681
Description
A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more resource-intensive. This issue can result in a large amount of computational consumption, causing a denial of service attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
jwcryptoPyPI | < 1.5.1 | 1.5.1 |
Affected products
14- cpe:/a:redhat:ansible_automation_platform:2
cpe:/a:redhat:enterprise_linux:8::appstream+ 4 more
- cpe:/a:redhat:enterprise_linux:8::appstreamrange: 8100020240416171943.823393f5
- cpe:/a:redhat:enterprise_linux:9::appstreamrange: 0:1.5.6-2.el9
- cpe:/o:redhat:enterprise_linux:7
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_arm_64:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0:*:*:*:*:*:*:*
- ghsa-coords2 versions
< 1.5.1+ 1 more
- (no CPE)range: < 1.5.1
- (no CPE)range: < 1.5.6-2.el9
Patches
Vulnerability mechanics
References
9- access.redhat.com/errata/RHSA-2024:3267nvdThird Party AdvisoryWEB
- access.redhat.com/security/cve/CVE-2023-6681nvdThird Party AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-cw2r-4p82-qv79ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-6681ghsaADVISORY
- access.redhat.com/errata/RHSA-2024:9281nvdWEB
- github.com/latchset/jwcrypto/commit/d2655d370586cb830e49acfb450f87598da60be8ghsaWEB
- github.com/latchset/jwcrypto/security/advisories/GHSA-cw2r-4p82-qv79ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/jwcrypto/PYSEC-2024-104.yamlghsaWEB
News mentions
0No linked articles in our index yet.