cbcvebase.
CVE-2024-21530
published 2024-10-02

CVE-2024-21530: Versions of the package cocoon before 0.4.0 are vulnerable to Reusing a Nonce, Key Pair in Encryption when the encrypt, wrap, and dump functions are…

PriorityP417medium4.5CVSS 3.1
AVLACHPRNUINSCCLILAN
EPSS
0.14%
3.8th percentile
Versions of the package cocoon before 0.4.0 are vulnerable to Reusing a Nonce, Key Pair in Encryption when the encrypt, wrap, and dump functions are sequentially called. An attacker can generate the same ciphertext by creating a new encrypted message with the same cocoon object. **Note:** The issue does NOT affect objects created with Cocoon::new which utilizes ThreadRng.

Affected

2 ranges
VendorProductVersion rangeFixed in
apachecocoon>= 0 < 0.4.00.4.0
apachecocoon>= 0.0.0-0 < 0.4.00.4.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.