{"id":"GHSA-92wp-jghr-hh87","summary":"Weak encryption in Ninja Core","details":"The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible leakage of sensitive information.","aliases":["CVE-2024-36823"],"modified":"2024-06-07T19:59:12.586366Z","published":"2024-06-07T00:30:37Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-06-07T19:36:27Z","nvd_published_at":"2024-06-06T22:15:10Z","cwe_ids":["CWE-326"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-36823"},{"type":"WEB","url":"https://github.com/ninjaframework/ninja/issues/759"},{"type":"PACKAGE","url":"https://github.com/ninjaframework/ninja"}],"affected":[{"package":{"name":"org.ninjaframework:ninja-core","ecosystem":"Maven","purl":"pkg:maven/org.ninjaframework/ninja-core"},"versions":["7.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-92wp-jghr-hh87/GHSA-92wp-jghr-hh87.json"}}],"schema_version":"1.9.0"}