Lucene search

K
osvGoogleOSV:GHSA-VJWC-5HFH-2VV5
HistoryMay 14, 2022 - 12:55 a.m.

Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J

2022-05-1400:55:57
Google
osv.dev
13
apache
wss4j
cryptographic algorithm
vulnerability
decryption
remote attackers
plaintext form
cve-2011-2487
software

EPSS

0.006

Percentile

79.3%

Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.