Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ww3w-592j-5qrw

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

SimpleSAMLphp Incorrect IV generation for encryption

The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector (IV).

Пакеты

Наименование

simplesamlphp/simplesamlphp

composer
Затронутые версииВерсия исправления

>= 1.14.0, < 1.14.12

1.14.12

EPSS

Процентиль: 24%
0.0008
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-326

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 8 лет назад

The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector (IV).

CVSS3: 5.9
nvd
больше 8 лет назад

The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector (IV).

CVSS3: 5.9
debian
больше 8 лет назад

The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAML ...

EPSS

Процентиль: 24%
0.0008
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-326