-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.ws.security:wss4j | maven | < 1.6.17 | 1.6.17 |
| org.apache.wss4j:wss4j-ws-security-dom | maven | >= 2.0.0, < 2.0.2 | 2.0.2 |
The patches directly modify the getRandomKey methods in both relevant EncryptedKeyProcessor classes to mitigate the vulnerability. These methods are directly related to the processing of encrypted keys and the potential leakage of decryption failure information.
A Semantic Attack on Google Gemini - Read the Latest Research