[MAVEN:GHSA-67FJ-6W6M-W5J8] Reversible One-Way Hash in io.github.javaezlib:JavaEZ

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

Impact

This weakness allows the force decryption of locked text by hackers. The issue is NOT critical for non-secure applications, however may be critical in a situation where the highest levels of security are required. This issue ONLY affects v1.6 and does not affect anything pre-1.6. Upgrading to 1.7 is advised.

Patches

The vulnerability has been patched in release 1.7.

Workarounds

Currently there is no way to fix the issue without upgrading.

References

CWE-327
CWE-328

For more information

If you have any questions or comments about this advisory:
* Open an issue in our issue tracker
* Email us at javaezlib@gmail.com

Package Affected Version
pkg:maven/io.github.javaezlib/JavaEZ = 1.6
Package Fixed Version
pkg:maven/io.github.javaezlib/JavaEZ = 1.7
ID
MAVEN:GHSA-67FJ-6W6M-W5J8
Severity
high
URL
https://github.com/advisories/GHSA-67fj-6w6m-w5j8
Published
2022-05-25T22:34:15
(2 years ago)
Modified
2023-07-21T19:28:04
(14 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/io.github.javaezlib/JavaEZ io.github.javaezlib JavaEZ = 1.6
Fixed pkg:maven/io.github.javaezlib/JavaEZ io.github.javaezlib JavaEZ = 1.7
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...