CVE-2024-21530
CVSS 3.1 Score 4.5 of 10 (medium)
Details
Published Oct 2, 2024
Updated: Oct 4, 2024
CWE ID 323
Summary
CVE-2024-21530 is a vulnerability affecting versions of the cocoon package prior to 0.4.0. The issue arises when the encrypt, wrap, and dump functions are used in sequence, resulting in the reuse of a nonce and key pair in encryption. An attacker can exploit this vulnerability to generate the same ciphertext, potentially leading to data disclosure or unauthorized access. However, objects created with Cocoon::new, which utilizes ThreadRng, are not impacted by this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cocoon