Vulnerabilities > Lockss

DATE CVE VULNERABILITY TITLE RISK
2023-12-15 CVE-2023-42183 Improper Encoding or Escaping of Output vulnerability in Lockss Classic Lockss Daemon 1.75.9/1.76.5
lockss-daemon (aka Classic LOCKSS Daemon) before 1.77.3 performs post-Unicode normalization, which may allow bypass of intended access restrictions, such as when U+1FEF is converted to a backtick.
network
low complexity
lockss CWE-116
5.3