Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cryptacular 跨站脚本漏洞
Vulnerability Description
Cryptacular是开源的用于 Java的Bouncy Castle Crypto API的补充。 cryptacular 存在跨站脚本漏洞,该漏洞源于在CiphertextHeader.java中解码操作期间过多的内存分配。
CVSS Information
N/A
Vulnerability Type
N/A