GO-2021-0102
Dashboard / Vulnerabilities / GO-2021-0102
GO-2021-0102
Published: 28 Jul 2021Last Modified: 20 May 2024
Aliases:
Summary: Panic in decryption in code.cloudfoundry.org/gorouter
Details: Due to improper input validation, a maliciously crafted input can cause a panic, due to incorrect nonce size. If this package is used to decrypt user supplied messages without checking the size of supplied nonces, this may be used as a vector for a denial of service attack.
References: https://github.com/cloudfoundry/gorouter/commit/b1b5c44e050f73b399b379ca63a42a2c5780a83f, https://www.cloudfoundry.org/blog/cve-2019-11289/
Affected packages
Package
Name: code.cloudfoundry.org/gorouter
Purl: pkg:golang/code.cloudfoundry.org/gorouter
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -0.0.0-20191101214924-b1b5c44e050f
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
