Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x64g-4xx9-fh6x

Опубликовано: 10 июн. 2020
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Denial of Service in Cryptacular

CiphertextHeader.java in Cryptacular before 1.2.4, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data.

Ссылки

Пакеты

Наименование

org.cryptacular:cryptacular

maven
Затронутые версииВерсия исправления

< 1.1.4

1.1.4

Наименование

org.cryptacular:cryptacular

maven
Затронутые версииВерсия исправления

>= 1.2.0, < 1.2.4

1.2.4

EPSS

Процентиль: 87%
0.03282
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
redhat
около 6 лет назад

CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data.

CVSS3: 7.5
nvd
около 6 лет назад

CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data.

EPSS

Процентиль: 87%
0.03282
Низкий

7.5 High

CVSS3

Дефекты

CWE-770