CVE-2023-43617 affects Croc versions up to 9.6.5, where a vulnerability allows for the partial disclosure of custom shared secrets to an untrusted Relay during the room name composition process. This medium-severity vulnerability (CVSS 5.3) has a low impact on confidentiality, requiring no user interaction or privileges, and can be exploited over the network. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.6.5CPE matchmatch criteria | cpe:2.3:a:schollz:croc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.