Lucene search

K
cvelistMitreCVELIST:CVE-2020-7226
HistoryJan 24, 2020 - 2:17 p.m.

CVE-2020-7226

2020-01-2414:17:16
mitre
www.cve.org
6

AI Score

8.4

Confidence

High

EPSS

0.018

Percentile

88.1%

CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with “new byte” may depend on untrusted input within the header of encoded data.

References

AI Score

8.4

Confidence

High

EPSS

0.018

Percentile

88.1%