Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r2r8-36pq-27cm

Опубликовано: 17 мая 2024
Источник: github
Github: Прошло ревью

Описание

nzo/url-encryptor-bundle Insecure default secret key and IV allowing anyone to decrypt values

Versions of nzo/url-encryptor-bundle prior to 5.0.1 and 4.3.2 are affected by a security vulnerability related to the lack of mandatory key and IV requirements. By default, the bundle uses the aes-256-ctr algorithm, which is susceptible to malleability attacks, potentially leading to Insecure Direct Object Reference (IDOR) vulnerabilities. Additionally, the reuse of keys enables users to decrypt and modify encrypted data if they can guess the plaintext of one ciphertext.

Пакеты

Наименование

nzo/url-encryptor-bundle

composer
Затронутые версииВерсия исправления

>= 5.0.0, < 5.0.1

5.0.1

Наименование

nzo/url-encryptor-bundle

composer
Затронутые версииВерсия исправления

>= 4.0.0, < 4.3.2

4.3.2