Логотип exploitDog
bind:CVE-2024-36121
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-36121

Количество 2

Количество 2

nvd логотип

CVE-2024-36121

больше 1 года назад

netty-incubator-codec-ohttp is the OHTTP implementation for netty. BoringSSLAEADContext keeps track of how many OHTTP responses have been sent and uses this sequence number to calculate the appropriate nonce to use with the encryption algorithm. Unfortunately, two separate errors combine which would allow an attacker to cause the sequence number to overflow and thus the nonce to repeat.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-g762-h86w-8749

больше 1 года назад

BoringSSLAEADContext in Netty Repeats Nonces

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-36121

netty-incubator-codec-ohttp is the OHTTP implementation for netty. BoringSSLAEADContext keeps track of how many OHTTP responses have been sent and uses this sequence number to calculate the appropriate nonce to use with the encryption algorithm. Unfortunately, two separate errors combine which would allow an attacker to cause the sequence number to overflow and thus the nonce to repeat.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-g762-h86w-8749

BoringSSLAEADContext in Netty Repeats Nonces

CVSS3: 5.9
0%
Низкий
больше 1 года назад

Уязвимостей на страницу