PT-2020-17550 · Branca · Branca
Published
2020-11-29
·
Updated
2022-09-02
·
CVE-2020-35918
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
branca versions prior to 0.10.0
Description
An issue was discovered where decoding tokens with invalid base62 data can cause the program to panic. This occurs when tokens with incorrect base62 encoding are supplied, which can lead to unexpected panics in decoding functions. The documentation incorrectly stated that an error should be reported instead of a panic.
Recommendations
For versions prior to 0.10.0, update to version 0.10.0 or later to resolve the issue. As a temporary workaround, consider validating base62 encoded tokens before passing them to decoding functions to minimize the risk of unexpected panics.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Branca