CVE-2024-21530

CVSS 3.1 Score 4.5 of 10 (medium)

Details

Published Oct 2, 2024
Updated: Oct 4, 2024
CWE ID 323

Summary

CVE-2024-21530 is a vulnerability affecting versions of the cocoon package prior to 0.4.0. The issue arises when the encrypt, wrap, and dump functions are used in sequence, resulting in the reuse of a nonce and key pair in encryption. An attacker can exploit this vulnerability to generate the same ciphertext, potentially leading to data disclosure or unauthorized access. However, objects created with Cocoon::new, which utilizes ThreadRng, are not impacted by this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share