Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r2jw-c95q-rj29

Опубликовано: 02 окт. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.3
CVSS3: 4.5

Описание

Duplicate Advisory: cocoon Reuses a Nonce, Key Pair in Encryption

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-6878-6wc2-pf5h. This link is maintained to preserve external references.

Original Description

Versions of the package cocoon before 0.4.0 are vulnerable to Reusing a Nonce, Key Pair in Encryption when the encrypt, wrap, and dump functions are sequentially called. An attacker can generate the same ciphertext by creating a new encrypted message with the same cocoon object.

Note: The issue does NOT affect objects created with Cocoon::new which utilizes ThreadRng.

Пакеты

Наименование

cocoon

rust
Затронутые версииВерсия исправления

< 0.4.0

0.4.0

6.3 Medium

CVSS4

4.5 Medium

CVSS3

Дефекты

CWE-323

6.3 Medium

CVSS4

4.5 Medium

CVSS3

Дефекты

CWE-323