CVE-2023-52892
PoC —CVSS 3.1
7.5 high
EPSS
<1%p31
Published
()
Modified
Description
In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to name confusion in X.509 certificate host verification.
- Vendors
- phpseclib
- Products
- phpseclib
- Weakness
- CWE-436
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.