{"id":"CVE-2024-31209","summary":"OpenID Connect client Atom Exhaustion in provider configuration worker ets table location","details":"oidcc is the OpenID Connect client library for Erlang. Denial of Service (DoS) by Atom exhaustion is possible by calling `oidcc_provider_configuration_worker:get_provider_configuration/1` or `oidcc_provider_configuration_worker:get_jwks/1`. This issue has been patched in version(s)`3.1.2` & `3.2.0-beta.3`.","aliases":["GHSA-mj35-2rgf-cv8p"],"modified":"2026-08-12T03:51:13.624142675Z","published":"2024-04-04T16:04:43.255Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/31xxx/CVE-2024-31209.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-400"]},"references":[{"type":"WEB","url":"https://github.com/erlef/oidcc/blob/018dbb53dd752cb1e331637d8e0e6a489ba1fae9/src/oidcc_provider_configuration_worker.erl#L385-L388"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/31xxx/CVE-2024-31209.json"},{"type":"ADVISORY","url":"https://github.com/erlef/oidcc/security/advisories/GHSA-mj35-2rgf-cv8p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-31209"},{"type":"FIX","url":"https://github.com/erlef/oidcc/commit/2f304d877c7e0613d6fd952d7feacbf40dbc355c"},{"type":"FIX","url":"https://github.com/erlef/oidcc/commit/48171fb62688fb4eec1ead0884aa501e0aa68649"},{"type":"FIX","url":"https://github.com/erlef/oidcc/commit/ac458ed88dc292aad6fa7343f6a53e73c560fb1a"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/erlef/oidcc","events":[{"introduced":"d14e5feb85515f397d344be44c58044c15b3318e"},{"introduced":"6d28af86770dccde52b53659b16baa6783fefae9"},{"introduced":"3a5da3c8d39770a20e5297dc71d22e8d049f918b"},{"fixed":"2463579d1d76fa74e4086a7c1a45fd963eca2add"},{"fixed":"feb21ec6c89bfad87208551b31e7da9be24eb6ef"},{"fixed":"62e438f15c70c6687fd58bd175c0794bfd8a2db1"},{"fixed":"2f304d877c7e0613d6fd952d7feacbf40dbc355c"},{"fixed":"48171fb62688fb4eec1ead0884aa501e0aa68649"},{"fixed":"ac458ed88dc292aad6fa7343f6a53e73c560fb1a"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"3.0.0"},{"fixed":"3.0.2"},{"introduced":"3.1.0"},{"fixed":"3.1.2"},{"introduced":"3.2.0-beta.1"},{"fixed":"3.2.0-beta.3"}]}}],"versions":["v3.0.1","v3.1.1","v3.2.0-beta.2","v3.2.0-beta.1","v3.1.0","v3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-31209.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H"}]}