Описание
The RSA 1.5 algorithm implementation in the JOSE_JWE class in JWE.php in jose-php before 2.2.1 lacks the Random Filling protection mechanism, which makes it easier for remote attackers to obtain cleartext data via a Million Message Attack (MMA).
Ссылки
- Third Party AdvisoryVDB Entry
- Patch
- Third Party AdvisoryVDB Entry
- Patch
Уязвимые конфигурации
Конфигурация 1Версия до 2.2.1 (исключая)
cpe:2.3:a:jose-php_project:jose-php:*:*:*:*:*:*:*:*
EPSS
Процентиль: 50%
0.00274
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 5.3
github
больше 3 лет назад
The RSA 1.5 algorithm implementation in the JOSE_JWE class in JWE.php in jose-php before 2.2.1 lacks the Random Filling protection mechanism, which makes it easier for remote attackers to obtain cleartext data via a Million Message Attack (MMA).
EPSS
Процентиль: 50%
0.00274
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200