Description
CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data.
Remediation
References
Related Vulnerabilities
Drupal Core 9.0.x Cross-Site Scripting (9.0.0 - 9.0.11)
WordPress Plugin Easy Social Icons Cross-Site Scripting (3.1.2)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-7859)
Dolibarr Incorrect Authorization Vulnerability (CVE-2022-0731)
PostgreSQL Improper Access Control Vulnerability (CVE-2019-10130)