VulnerAlert



JAVA
05-06-2025 21:20

CVE-2020-8929 Vulnerabilidad documentada

5.3 MEDIUM
Tags
#java
#change
#problem
#allow
#attack
Descripción
A mis-handling of invalid unicode characters in the Java implementation Tink versions prior to 1.5 allows an attacker change ID part a ciphertext, which result creation second ciphertext that can decrypt same plaintext. This be problem with encrypting deterministic AEAD single key, and rely on unique ciphertext-per-plaintext.
https://github.com/google/tink/commit/93d839a5865b9d950dffdc9d0bc99b71280a8899
https://github.com/google/tink/security/advisories/GHSA-g5vf-v6wf-7w2r
https://github.com/google/tink/commit/93d839a5865b9d950dffdc9d0bc99b71280a8899
https://github.com/google/tink/security/advisories/GHSA-g5vf-v6wf-7w2r
Referencia
Link externo
Ver detalles

Fuente
https://nvd.nist.gov/vuln/detail/CVE-2020-8929
Resultados similares
Coincidentes en almenos en 50% de los tags
12-12-2025 CVE-2025-66214
Ladybug adds message-based debugging, unit, system, and regression testing to Java applications...
Ver información
12-12-2025
React2Shell Exploitation Escalates into Large-Scale Global Attacks, Forcing Emergency Mitigatio...
Ver información
Icons made by Freepik from www.flaticon.com
Este Proyecto fue cofinanciado por el Consejo Nacional de Ciencia y Tecnología (CONACYT) a través del PROINNOVA 2021/2023
Proyecto realizado por