CyberRota Analysis
AI-GeneratedApplications utilizing AesBytesEncryptor with a two-argument constructor or a null IV generator in CBC mode are vulnerable to encryption weaknesses due to the use of a null (all-zero) initialization vector. This flaw can lead to predictable ciphertext, potentially allowing attackers to decrypt sensitive data or perform other cryptographic attacks. Organizations using affected versions of Spring Security should prioritize remediation to safeguard their data integrity and confidentiality.
Original NVD Description
Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as the encryption mode encrypt data with AES/CBC using a null (all-zero) initialization vector. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25
Related CVEs
Other vulnerabilities affecting the same vendor(s)