CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.cryptacular:cryptacular(Maven) | 0 | 1.1.4 | N/A |
| org.cryptacular:cryptacular(Maven) | 1.2.0 | 1.2.4 | N/A |
CVSS Metrics