CVE-2023-52096: SQL Injection
SteVe Community ocpp-jaxb before 0.0.8 generates invalid timestamps such as ones with month 00 in certain situations (such as when an application receives a StartTransaction Open Charge Point Protocol message with a timestamp parameter of 1000000). This may lead to a SQL exception in applications, and may undermine the integrity of transaction records.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52096?
CVE-2023-52096 is classified as a moderate severity vulnerability due to its potential to cause SQL exceptions.
How do I fix CVE-2023-52096?
To fix CVE-2023-52096, update the SteVe Community ocpp-jaxb library to version 0.0.8 or later.
What impact does CVE-2023-52096 have on applications?
CVE-2023-52096 can lead to SQL exceptions in applications that handle invalid timestamps generated by the library.
What versions of the software are affected by CVE-2023-52096?
CVE-2023-52096 affects versions of SteVe Community ocpp-jaxb prior to 0.0.8.
What kind of timestamps are generated by the vulnerability in CVE-2023-52096?
CVE-2023-52096 generates invalid timestamps, such as those with a month value of 00.