ZeroHour

CVE-2023-52892

PoC
CVSS 3.1
7.5 high
EPSS
<1%p31
Published
()
Modified
Description

In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to name confusion in X.509 certificate host verification.

Vendors
phpseclib
Products
phpseclib
Weakness
CWE-436
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.