CVE-2024-37370 - log back

CVE-2024-37370 edited at 06 Jul 2024 16:36:50
Severity
- High
+ Medium
CVE-2024-37370 edited at 06 Jul 2024 16:36:08
Remote
- Unknown
+ Remote
Type
- Unknown
+ Content spoofing
CVE-2024-37370 edited at 06 Jul 2024 16:33:53
References
+ https://github.com/krb5/krb5/commit/55fbf435edbe2e92dd8101669b1ce7144bc96fef
CVE-2024-37370 edited at 06 Jul 2024 16:33:12
Severity
- Unknown
+ High
CVE-2024-37370 edited at 06 Jul 2024 16:32:44
Description
+ In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.
References
Notes
CVE-2024-37370 created at 06 Jul 2024 16:29:54