Lucene search

K
osvGoogleOSV:GO-2021-0102
HistoryJul 28, 2021 - 6:08 p.m.

Panic in decryption in code.cloudfoundry.org/gorouter

2021-07-2818:08:05
Google
osv.dev
20
decryption
input validation
nonce size
denial of service
attack
code.cloudfoundry.org/gorouter
software

AI Score

8.3

Confidence

High

EPSS

0.001

Percentile

42.5%

Due to improper input validation, a maliciously crafted input can cause a panic, due to incorrect nonce size. If this package is used to decrypt user supplied messages without checking the size of supplied nonces, this may be used as a vector for a denial of service attack.

AI Score

8.3

Confidence

High

EPSS

0.001

Percentile

42.5%