logo

GHSA-r2r8-36pq-27cm nzo/url-encryptor-bundle

Package

Manager: composer
Name: nzo/url-encryptor-bundle
Vulnerable Version: >=5.0.0 <5.0.1 || >=4.0.0 <4.3.2

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C

CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: N/A pctlN/A

Details

nzo/url-encryptor-bundle Insecure default secret key and IV allowing anyone to decrypt values Versions of nzo/url-encryptor-bundle prior to 5.0.1 and 4.3.2 are affected by a security vulnerability related to the lack of mandatory key and IV requirements. By default, the bundle uses the aes-256-ctr algorithm, which is susceptible to malleability attacks, potentially leading to Insecure Direct Object Reference (IDOR) vulnerabilities. Additionally, the reuse of keys enables users to decrypt and modify encrypted data if they can guess the plaintext of one ciphertext.

Metadata

Created: 2024-05-17T23:06:52Z
Modified: 2024-05-17T23:06:52Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-r2r8-36pq-27cm/GHSA-r2r8-36pq-27cm.json
CWE IDs: []
Alternative ID: N/A
Finding: F034
Auto approve: 1