Please patch CVEs for package cryptacular version 1.1.0 INFO (CVEs are): cryptacular 1.1.0 cves found CVE-2020-7226 Desc: CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data. Link: https://nvd.nist.gov/vuln/detail/CVE-2020-7226 Severity: HIGH
*** Bug 13698 has been marked as a duplicate of this bug. ***
*** Bug 13507 has been marked as a duplicate of this bug. ***
Затрагивает версию 1.2.3.,не для нас.
secteam_verified