In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade openmls to version 0.7.2 or higher.
Affected versions of this package are vulnerable to Improper Check for Unusual or Exceptional Conditions due to improper validation of tag lengths in the authentication process. An attacker can bypass secondary authentication guarantees by crafting messages with truncated or empty tags that are still accepted as valid.
Note: This is only exploitable if the application uses public MLS messages and supports proposals by reference (standalone proposals).