PT-2023-28878 · Croc · Croc

Matthias Gerstner

·

Published

2023-09-19

·

Updated

2024-09-25

·

CVE-2023-43617

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Croc versions prior to 9.6.16
Description An issue was discovered in Croc where parts of a custom shared secret may be divulged to an untrusted Relay when composing a room name. This occurs when a custom shared secret is used.
Recommendations For Croc versions prior to 9.6.16, update to version 9.6.16 or later to resolve the issue. As a temporary workaround, consider avoiding the use of custom shared secrets until a patch is applied. Restrict access to untrusted Relays to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2023-43617
GHSA-HP56-XVF4-G6WR
GO-2023-2072

Affected Products

Croc