QID 980301
QID 980301: Java (maven) Security Update for org.cryptacular:cryptacular (GHSA-x64g-4xx9-fh6x)
CiphertextHeader.java in Cryptacular before 1.2.4, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-x64g-4xx9-fh6x for updates pertaining to this vulnerability.
Vendor References
- GHSA-x64g-4xx9-fh6x -
github.com/advisories/GHSA-x64g-4xx9-fh6x
CVEs related to QID 980301
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-x64g-4xx9-fh6x | org.cryptacular:cryptacular |
|