CVE-2023-52096

SteVe Community ocpp-jaxb before 0.0.8 generates invalid timestamps such as ones with month 00 in certain situations (such as when an application receives a StartTransaction Open Charge Point Protocol message with a timestamp parameter of 1000000). This may lead to a SQL exception in applications, and may undermine the integrity of transaction records.
Configurations

Configuration 1 (hide)

cpe:2.3:a:steve-community:ocpp-jaxb:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:39

Type Values Removed Values Added
References () https://github.com/steve-community/ocpp-jaxb/compare/0.0.7...0.0.8 - Product () https://github.com/steve-community/ocpp-jaxb/compare/0.0.7...0.0.8 - Product
References () https://github.com/steve-community/ocpp-jaxb/issues/13 - Exploit, Issue Tracking () https://github.com/steve-community/ocpp-jaxb/issues/13 - Exploit, Issue Tracking
References () https://github.com/steve-community/steve/issues/1292 - Exploit, Issue Tracking, Vendor Advisory () https://github.com/steve-community/steve/issues/1292 - Exploit, Issue Tracking, Vendor Advisory

04 Jan 2024, 03:38

Type Values Removed Values Added
CPE cpe:2.3:a:steve-community:ocpp-jaxb:*:*:*:*:*:*:*:*
References () https://github.com/steve-community/ocpp-jaxb/compare/0.0.7...0.0.8 - () https://github.com/steve-community/ocpp-jaxb/compare/0.0.7...0.0.8 - Product
References () https://github.com/steve-community/ocpp-jaxb/issues/13 - () https://github.com/steve-community/ocpp-jaxb/issues/13 - Exploit, Issue Tracking
References () https://github.com/steve-community/steve/issues/1292 - () https://github.com/steve-community/steve/issues/1292 - Exploit, Issue Tracking, Vendor Advisory
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Steve-community ocpp-jaxb
Steve-community

27 Dec 2023, 18:24

Type Values Removed Values Added
Summary
  • (es) SteVe Community ocpp-jaxb anterior a 0.0.8 genera marcas de tiempo no válidas, como las del mes 00 en determinadas situaciones (como cuando una aplicación recibe un Open Charge Point Protocol de StartTransaction con un parámetro de marca de tiempo de 1000000). Esto puede provocar una excepción de SQL en las aplicaciones y puede socavar la integridad de los registros de transacciones.

26 Dec 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-26 23:15

Updated : 2024-11-21 08:39


NVD link : CVE-2023-52096

Mitre link : CVE-2023-52096

CVE.ORG link : CVE-2023-52096


JSON object : View

Products Affected

steve-community

  • ocpp-jaxb
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')