CVE-2020-7226

HIGH

Cryptacular < 1.1.4 - Denial of Service via Excessive Memory Allocation in CiphertextHeader

Title source: llm
STIX 2.1

Description

CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data.

References (19)

Core 19
Core References
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2021.html
Exploit, Third Party Advisory x_refsource_misc
https://github.com/vt-middleware/cryptacular/issues/52
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2022.html
Patch, Third Party Advisory x_refsource_misc
https://github.com/apereo/cas/pull/4685

Scores

CVSS v3 7.5
EPSS 0.0333
EPSS Percentile 87.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-770
Status published
Products (7)
oracle/communications_services_gatekeeper 7.0
oracle/webcenter_sites 12.2.1.3.0
oracle/webcenter_sites 12.2.1.4.0
oracle/weblogic_server 12.2.1.4.0
oracle/weblogic_server 14.1.1.0.0
org.cryptacular/cryptacular 0 - 1.1.4Maven
vt/cryptacular < 1.1.4
Published Jan 24, 2020
Tracked Since Feb 18, 2026