It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks.
{ "nvd_published_at": "2021-06-22T12:15:00Z", "github_reviewed_at": "2021-06-24T20:07:33Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-649" ] }