GHSA-c9rv-3jmq-527w
Dashboard / Vulnerabilities / GHSA-c9rv-3jmq-527w
GHSA-c9rv-3jmq-527w
Published: 25 Aug 2021Last Modified: 8 Nov 2023
Aliases:
Summary: Unexpected panic when decoding tokens in branca
Details: Prior to 0.10.0 it was possible to have both decoding functions panic unexpectedly, by supplying tokens with an incorrect base62 encoding. The documentation stated that an error should have been reported instead.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-35918, https://github.com/return/branca/issues/24, https://github.com/tuupola/branca-spec/issues/22, https://github.com/return/branca/commit/7da3274bd99b05dce9c3f9b4b129d0145c71820b, https://github.com/return/branca, https://rustsec.org/advisories/RUSTSEC-2020-0075.html
Affected packages
Package
Name: branca
Purl: pkg:cargo/branca
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -0.10.0
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
