Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wx54-3278-m5g4

Опубликовано: 20 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Integer overflow in BCrypt class in Spring Security

Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE.

Пакеты

Наименование

org.springframework.security:spring-security-core

maven
Затронутые версииВерсия исправления

>= 5.2.0.RELEASE, < 5.5.7

5.5.7

Наименование

org.springframework.security:spring-security-core

maven
Затронутые версииВерсия исправления

>= 5.6.0, < 5.6.4

5.6.4

EPSS

Процентиль: 58%
0.0036
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 3 лет назад

Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE.

CVSS3: 5.3
redhat
больше 3 лет назад

Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE.

CVSS3: 5.3
nvd
больше 3 лет назад

Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE.

CVSS3: 5.3
debian
больше 3 лет назад

Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, a ...

EPSS

Процентиль: 58%
0.0036
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-190