First published: Tue Dec 26 2023(Updated: )
SteVe Community ocpp-jaxb before 0.0.8 generates invalid timestamps such as ones with month 00 in certain situations (such as when an application receives a StartTransaction Open Charge Point Protocol message with a timestamp parameter of 1000000). This may lead to a SQL exception in applications, and may undermine the integrity of transaction records.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Steve-community Steve | <0.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-52096 is classified as a moderate severity vulnerability due to its potential to cause SQL exceptions.
To fix CVE-2023-52096, update the SteVe Community ocpp-jaxb library to version 0.0.8 or later.
CVE-2023-52096 can lead to SQL exceptions in applications that handle invalid timestamps generated by the library.
CVE-2023-52096 affects versions of SteVe Community ocpp-jaxb prior to 0.0.8.
CVE-2023-52096 generates invalid timestamps, such as those with a month value of 00.