[MAVEN:GHSA-3GP6-HHFW-4GQX] Padding oracle attacks

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks.

Package Affected Version
pkg:maven/org.owasp.esapi/esapi < 2.0GA
Package Fixed Version
pkg:maven/org.owasp.esapi/esapi = 2.0GA
ID
MAVEN:GHSA-3GP6-HHFW-4GQX
Severity
moderate
URL
https://github.com/advisories/GHSA-3gp6-hhfw-4gqx
Published
2021-08-13T15:22:24
(3 years ago)
Modified
2023-02-01T05:06:00
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.owasp.esapi/esapi org.owasp.esapi esapi < 2.0GA
Fixed pkg:maven/org.owasp.esapi/esapi org.owasp.esapi esapi = 2.0GA
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...