VYPR

Tink Java

by Google

CVEs (1)

  • CVE-2020-8929MedOct 19, 2020
    risk 0.27cvss 5.3epss 0.00

    A mis-handling of invalid unicode characters in the Java implementation of Tink versions prior to 1.5 allows an attacker to change the ID part of a ciphertext, which result in the creation of a second ciphertext that can decrypt to the same plaintext. This can be a problem with…