Nablarch Incomplete Cryptography
Critical severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Aug 3, 2023
Package
Affected versions
< 1.5.1
Patched versions
1.5.1
Description
Published by the National Vulnerability Database
Mar 12, 2019
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 19, 2023
Last updated
Aug 3, 2023
An incomplete cryptography of the data store function by using hidden tag in Nablarch 5 (5, and 5u1 to 5u13) allows remote attackers to obtain information of the stored data, to register invalid value, or alter the value via unspecified vectors.
References