HIGH
GHSA-94g3-g5v7-q4jg
phpseclib's AES-CBC unpadding susceptible to padding oracle timing attack
Quick fix
GHSA-94g3-g5v7-q4jg — phpseclib/phpseclib: upgrade to the fixed version with the command below.
composer require phpseclib/phpseclib:^3.0.50Details
### Impact Those using AES in CBC mode may be susceptible to a padding oracle timing attack.
### Patches https://github.com/phpseclib/phpseclib/commit/ccc21aef71eb170e9bf819b167e67d1fd9e6e788
### Workarounds Use AES in CTR, CFB or OFB modes
### References https://github.com/phpseclib/phpseclib/commit/ccc21aef71eb170e9bf819b167e67d1fd9e6e788
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/phpseclib/phpseclib
Introduced in:
3.0.0Fixed in: 3.0.50Fix
composer require phpseclib/phpseclib:^3.0.50Packagist/phpseclib/phpseclib
Introduced in:
2.0.0Fixed in: 2.0.52Fix
composer require phpseclib/phpseclib:^2.0.52Packagist/phpseclib/phpseclib
Introduced in:
0.1.1Fixed in: 1.0.27Fix
composer require phpseclib/phpseclib:^1.0.27