Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vjwc-5hfh-2vv5

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J

Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.

Пакеты

Наименование

org.apache.ws.security:wss4j

maven
Затронутые версииВерсия исправления

< 1.6.17

1.6.17

Наименование

org.apache.wss4j:wss4j-ws-security-dom

maven
Затронутые версииВерсия исправления

>= 2.0.0, < 2.0.2

2.0.2

EPSS

Процентиль: 90%
0.0521
Низкий

7.5 High

CVSS3

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.

redhat
почти 11 лет назад

Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.

CVSS3: 7.5
nvd
больше 8 лет назад

Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.

CVSS3: 7.5
debian
больше 8 лет назад

Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks inf ...

EPSS

Процентиль: 90%
0.0521
Низкий

7.5 High

CVSS3

Дефекты

CWE-327