---
title: "CVE-2022-36083\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2022-36083?format=md
keywords: index, follow
---

# CVE-2022-36083

Publication date 7 September 2022

Last updated 11 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.3 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2022-36083?format=md#impact-score)

Toggle side navigation

## Description

JOSE is "JSON Web Almost Everything" - JWA, JWS, JWE, JWT, JWK, JWKS with
no dependencies using runtime's native crypto in Node.js, Browser,
Cloudflare Workers, Electron, and Deno. The PBKDF2-based JWE key management
algorithms expect a JOSE Header Parameter named `p2c` PBES2 Count, which
determines how many PBKDF2 iterations must be executed in order to derive a
CEK wrapping key. The purpose of this parameter is to intentionally slow
down the key derivation function in order to make password brute-force and
dictionary attacks more expensive. This makes the PBES2 algorithms
unsuitable for situations where the JWE is coming from an untrusted source:
an adversary can intentionally pick an extremely high PBES2 Count value,
that will initiate a CPU-bound computation that may take an unreasonable
amount of time to finish. Under certain conditions, it is possible to have
the user's environment consume unreasonable amount of CPU time. The impact
is limited only to users utilizing the JWE decryption APIs with symmetric
secrets to decrypt JWEs from untrusted parties who do not limit the
accepted JWE Key Management Algorithms (`alg` Header Parameter) using the
`keyManagementAlgorithms` (or `algorithms` in v1.x) decryption option or
through other means. The `v1.28.2`, `v2.0.6`, `v3.20.4`, and `v4.9.2`
releases limit the maximum PBKDF2 iteration count to `10000` by default. It
is possible to adjust this limit with a newly introduced `maxPBES2Count`
decryption option. If users are unable to upgrade their required library
version, they have two options depending on whether they expect to receive
JWEs using any of the three PBKDF2-based JWE key management algorithms.
They can use the `keyManagementAlgorithms` decryption option to disable
accepting PBKDF2 altogether, or they can inspect the JOSE Header prior to
using the decryption API and limit the PBKDF2 iteration count (`p2c` Header
Parameter).

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| jose | 26.04 LTS resolute | Needs evaluation |
| 25.10 questing | Ignored end of life, was needs-triage |
| 25.04 plucky | Ignored end of life, was needs-triage |
| 24.10 oracular | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Needs evaluation |
| 23.10 mantic | Ignored end of life, was needs-triage |
| 23.04 lunar | Ignored end of life, was needs-triage |
| 22.10 kinetic | Ignored end of life, was needs-triage |
| 22.04 LTS jammy | Not affected |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| node-jose | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Vulnerable |
| 20.04 LTS focal | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.3 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | Low |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.3 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36083)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-36083)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2022-36083)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2022-36083)

### Other references

* <https://github.com/panva/jose/security/advisories/GHSA-jv3g-j58f-9mq9>
* <https://github.com/panva/jose/commit/03d6d013bf6e070e85adfe5731f526978e3e8e4d (v4.9.2)>
* <https://www.cve.org/CVERecord?id=CVE-2022-36083>
