Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ff7q-6vwh-v9m4

Опубликовано: 28 июн. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Name confusion in x509 Subject Alternative Name fields

In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to name confusion in X.509 certificate host verification.

Пакеты

Наименование

phpseclib/phpseclib

composer
Затронутые версииВерсия исправления

< 1.0.22

1.0.22

Наименование

phpseclib/phpseclib

composer
Затронутые версииВерсия исправления

>= 2.0.0, < 2.0.46

2.0.46

Наименование

phpseclib/phpseclib

composer
Затронутые версииВерсия исправления

>= 3.0.0, < 3.0.33

3.0.33

EPSS

Процентиль: 37%
0.00154
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-436

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 года назад

In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to name confusion in X.509 certificate host verification.

CVSS3: 7.5
nvd
около 1 года назад

In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to name confusion in X.509 certificate host verification.

CVSS3: 7.5
debian
около 1 года назад

In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, ...

CVSS3: 7.5
redos
12 месяцев назад

Уязвимость php-phpseclib

EPSS

Процентиль: 37%
0.00154
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-436