Lucene search

K
osvGoogleOSV:GHSA-X64G-4XX9-FH6X
HistoryJun 10, 2020 - 8:02 p.m.

Denial of Service in Cryptacular

2020-06-1020:02:58
Google
osv.dev
26

EPSS

0.018

Percentile

88.1%

CiphertextHeader.java in Cryptacular before 1.2.4, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data.

References

EPSS

0.018

Percentile

88.1%