CVE-2021-30130

phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.
References
Link Resource
https://github.com/phpseclib/phpseclib/releases/tag/2.0.31 Release Notes Third Party Advisory
https://github.com/phpseclib/phpseclib/pull/1635 Third Party Advisory
https://github.com/phpseclib/phpseclib/releases/tag/3.0.7 Release Notes Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:phpseclib:phpseclib:*:*:*:*:*:*:*:*
cpe:2.3:a:phpseclib:phpseclib:*:*:*:*:*:*:*:*

Information

Published : 2021-04-06 15:15

Updated : 2021-04-20 19:22


NVD link : CVE-2021-30130

Mitre link : CVE-2021-30130


JSON object : View

Products Affected

phpseclib

  • phpseclib
CWE
CWE-347

Improper Verification of Cryptographic Signature