CVE-2023-51775 in jose library embedded in TomEE 9.1.2

COURTAULT Francois <[email protected]> Fri, 15 Mar 2024 14:56:11 +0000
Newsgroups gmane.comp.java.openejb.user
Message-ID <MR1P264MB23550F30AB91243A524A8A769D282__4640.89583126537$1710514671$gmane$org@MR1P264MB2355.FRAP264.PROD.OUTLOOK.COM>
THALES GROUP LIMITED DISTRIBUTION to email recipients

Hello everyone,

The CVE 2023-51775 (Sonatype CVSS 3: 8.6) has been raised end of February 2024.
jose4j-0.9.3.jar has this vulnerability.

Is it safe/ok to replace this version by jose4j-0.9.6.jar released the 6th of March 2024 ?

Best Regards.