Vulnerability Description
The AES encryption project 7.x and 8.x for Drupal does not sufficiently prevent attackers from decrypting data, aka SA-CONTRIB-2017-027. NOTE: This project is not covered by Drupal's security advisory policy.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aes Encryption Project | Aes Encryption | >= 7.x-1.4, <= 7.x-1.10 |
Related Weaknesses (CWE)
References
- https://www.drupal.org/node/2857028Third Party Advisory
- https://www.drupal.org/node/2857028Third Party Advisory
FAQ
What is CVE-2017-20001?
CVE-2017-20001 is a vulnerability with a CVSS score of 7.5 (HIGH). The AES encryption project 7.x and 8.x for Drupal does not sufficiently prevent attackers from decrypting data, aka SA-CONTRIB-2017-027. NOTE: This project is not covered by Drupal's security advisory...
How severe is CVE-2017-20001?
CVE-2017-20001 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-20001?
Check the references section above for vendor advisories and patch information. Affected products include: Aes Encryption Project Aes Encryption.