CyberRota Analysis
AI-GeneratedApache WSS4J is vulnerable to accepting attacker-controlled derived-key lengths and offsets, potentially leading to the use of cryptographically weak keys or excessive resource consumption during the processing of WS-Security messages. This could compromise the security of applications relying on this library and degrade performance. Organizations using affected versions should prioritize upgrading to versions 4.0.2, 3.0.6, or 2.4.4 to mitigate these risks.
Original NVD Description
Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted WS-Security messages. The fixes enforce a minimum key length of 16 bytes, a maximum length of 512 bytes, and a maximum offset of 4096 bytes. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)