Описание
The Cloud Functions subsystem in OpenTrace 1.0 might allow fabrication attacks by making billions of TempID requests before an AES-256-GCM key rotation occurs.
Ссылки
- Issue TrackingThird Party Advisory
- Issue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:bluetrace:opentrace:1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 26%
0.00092
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-327
Связанные уязвимости
github
больше 3 лет назад
The Cloud Functions subsystem in OpenTrace 1.0 might allow fabrication attacks by making billions of TempID requests before an AES-256-GCM key rotation occurs.
EPSS
Процентиль: 26%
0.00092
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-327