PT-2020-8471 · Unknown+1 · Aes Encryption Project+1
Heine Deelstra
·
Published
2020-12-31
·
Updated
2021-01-12
·
CVE-2017-20001
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
AES encryption project versions 7.x through 8.x
Description:
The AES encryption project for Drupal does not sufficiently prevent attackers from decrypting data. This issue is not covered by Drupal's security advisory policy.
Recommendations:
For versions 7.x through 8.x, update to a version that includes the necessary security patches to prevent data decryption by attackers.
Fix
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aes Encryption Project
Drupal