pocoproject poco
cpe:2.3:a:pocoproject:poco:*:*:*:*:*:*:*
- <= 1.14.1-release
A vulnerability exists in POCO C++ Libraries version 1.14.1-release and prior, due to weak encryption practices. The implementation of JSON Web Signatures (JWS) uses HMAC and RSA key lengths that fall short of recommended security standards, potentially leading to vulnerabilities and attacks.
The weak encryption can be exploited to compromise the integrity and security of cryptographic operations, allowing for potential attacks that could undermine the application's security.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.