Technical information leak In org.owasp.esapi:esapi
Description
Padding oracle attacks It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
maven | 2.0ga |
Aliases
1. 2. 3. 4.
References
1. 2.