Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ff7q-6vwh-v9m4

Опубликовано: 28 июн. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Name confusion in x509 Subject Alternative Name fields

In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to name confusion in X.509 certificate host verification.

Пакеты

Наименование

phpseclib/phpseclib

composer
Затронутые версииВерсия исправления

< 1.0.22

1.0.22

Наименование

phpseclib/phpseclib

composer
Затронутые версииВерсия исправления

>= 2.0.0, < 2.0.46

2.0.46

Наименование

phpseclib/phpseclib

composer
Затронутые версииВерсия исправления

>= 3.0.0, < 3.0.33

3.0.33

EPSS

Процентиль: 40%
0.00183
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-436

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to name confusion in X.509 certificate host verification.

CVSS3: 7.5
nvd
больше 1 года назад

In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to name confusion in X.509 certificate host verification.

CVSS3: 7.5
debian
больше 1 года назад

In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, ...

CVSS3: 7.5
redos
больше 1 года назад

Уязвимость php-phpseclib

EPSS

Процентиль: 40%
0.00183
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-436