Jahlives

Openssl Encrypt

66 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 17.08.2026 11:04:50
  • Zuletzt bearbeitet 01.09.2026 15:27:00

openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always showing zero restored modules and corrupting audit trails. Additionally, a race condition exists between module hid...

  • EPSS 0.27%
  • Veröffentlicht 17.08.2026 11:04:49
  • Zuletzt bearbeitet 01.09.2026 15:27:11

openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugin_id parameter is not sanitized before constructing the plugin config directory path. Attackers can declare a malicious plugin_id ...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 17.08.2026 11:04:49
  • Zuletzt bearbeitet 01.09.2026 15:27:18

openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers can import pathlib or io modules to read and write arbitr...

  • EPSS 0.13%
  • Veröffentlicht 17.08.2026 11:04:48
  • Zuletzt bearbeitet 31.08.2026 15:49:27

openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProxyConfig trusted_proxies. Attackers on private networks can forge client certificate headers to bypas...

  • EPSS 0.28%
  • Veröffentlicht 17.08.2026 11:04:47
  • Zuletzt bearbeitet 08.10.2026 16:17:40

openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of any user who ...

  • EPSS 0.31%
  • Veröffentlicht 17.08.2026 11:04:47
  • Zuletzt bearbeitet 08.10.2026 16:17:40

openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unauthorized ac...

  • EPSS 0.26%
  • Veröffentlicht 17.08.2026 11:04:46
  • Zuletzt bearbeitet 08.10.2026 16:17:39

openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger database errors to extract sensitive informati...

  • EPSS 0.37%
  • Veröffentlicht 17.08.2026 11:04:45
  • Zuletzt bearbeitet 08.10.2026 16:17:39

openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on server restart. Attackers can distribute authentication attempts across multiple server instances or ...

  • EPSS 0.26%
  • Veröffentlicht 17.08.2026 11:04:44
  • Zuletzt bearbeitet 08.10.2026 16:17:39

openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clients to revoke any other client's key. Attackers can revoke arbitrary keys by providing a valid ML-DSA ...

  • EPSS 0.2%
  • Veröffentlicht 17.08.2026 11:04:44
  • Zuletzt bearbeitet 08.10.2026 16:17:39

openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without verifying signatures. Attackers can call from_dict() followed by to_identity() without signature verific...