Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m2gh-w3fj-x92v

Опубликовано: 27 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own while maintaining the claimed fingerprint, enabling silent key substitution where encryption uses attacker keys and signature verification appears valid.

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own while maintaining the claimed fingerprint, enabling silent key substitution where encryption uses attacker keys and signature verification appears valid.

EPSS

Процентиль: 4%
0.00139
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 9.8
nvd
17 дней назад

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own while maintaining the claimed fingerprint, enabling silent key substitution where encryption uses attacker keys and signature verification appears valid.

EPSS

Процентиль: 4%
0.00139
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-345