Descripción
A mis-handling of invalid unicode characters in the Java implementation Tink versions prior to 1.5 allows an attacker change ID part a ciphertext, which result creation second ciphertext that can decrypt same plaintext. This be problem with encrypting deterministic AEAD single key, and rely on unique ciphertext-per-plaintext.
https://github.com/google/tink/commit/93d839a5865b9d950dffdc9d0bc99b71280a8899
https://github.com/google/tink/security/advisories/GHSA-g5vf-v6wf-7w2r
https://github.com/google/tink/commit/93d839a5865b9d950dffdc9d0bc99b71280a8899
https://github.com/google/tink/security/advisories/GHSA-g5vf-v6wf-7w2r