icon

We found results for “

CVE-2023-52892

Good to know:

icon

Date: June 26, 2024

In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to name confusion in X.509 certificate host verification.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Interpretation Conflict

CWE-436

Top Fix

icon

Upgrade Version

Upgrade to version phpseclib/phpseclib-1.0.22,2.0.46,3.0.33

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us