Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-7226

Опубликовано: 24 янв. 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7cryptacularNot affected
Red Hat JBoss Fuse 6cryptacularOut of support scope
Red Hat OpenShift Application RuntimescryptacularAffected
Red Hat Process Automation 7cryptacularNot affected
Red Hat Fuse 7.8.0cryptacularFixedRHSA-2020:556816.12.2020
Red Hat JBoss EAP 7cryptacularFixedRHSA-2020:251510.06.2020
Red Hat JBoss EAP 7.2cryptacularFixedRHSA-2020:206111.05.2020
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6eap7-activemq-artemisFixedRHSA-2020:205811.05.2020
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6eap7-apache-cxfFixedRHSA-2020:205811.05.2020
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6eap7-bouncycastleFixedRHSA-2020:205811.05.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=1801380cryptacular: excessive memory allocation during a decode operation

EPSS

Процентиль: 87%
0.03282
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 6 лет назад

CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data.

CVSS3: 7.5
github
больше 5 лет назад

Denial of Service in Cryptacular

EPSS

Процентиль: 87%
0.03282
Низкий

7.5 High

CVSS3