Описание
Archery v1.10.0 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:archerydms:archery:1.9.0:*:*:*:*:*:*:*
EPSS
Процентиль: 37%
0.00155
Низкий
7.5 High
CVSS3
Дефекты
CWE-798
Связанные уязвимости
CVSS3: 7.5
github
около 2 лет назад
Archery v1.10.0 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications.
EPSS
Процентиль: 37%
0.00155
Низкий
7.5 High
CVSS3
Дефекты
CWE-798