CVE-2024-36823

The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible leakage of sensitive information.
References
Link Resource
https://github.com/ninjaframework/ninja/issues Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:ninjaframework:ninja:7.0.0:*:*:*:*:*:*:*

History

17 Jul 2024, 14:41

Type Values Removed Values Added
CPE cpe:2.3:a:ninjaframework:ninja:7.0.0:*:*:*:*:*:*:*
CWE CWE-326
References () https://github.com/ninjaframework/ninja/issues - () https://github.com/ninjaframework/ninja/issues - Issue Tracking
First Time Ninjaframework
Ninjaframework ninja
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

07 Jun 2024, 14:56

Type Values Removed Values Added
Summary
  • (es) Se descubrió que la función encrypt() de Ninja Core v7.0.0 utiliza un algoritmo criptográfico débil, lo que provoca una posible fuga de información confidencial.

06 Jun 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-06 22:15

Updated : 2024-07-17 14:41


NVD link : CVE-2024-36823

Mitre link : CVE-2024-36823

CVE.ORG link : CVE-2024-36823


JSON object : View

Products Affected

ninjaframework

  • ninja
CWE
CWE-326

Inadequate Encryption Strength