Description
ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-1250 | ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution. |
References
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-05T13:25:16.804Z
Reserved: 2016-11-30T00:00:00.000Z
Link: CVE-2017-0897
No data.
Status : Deferred
Published: 2017-06-22T21:29:00.183
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-0897
No data.
OpenCVE Enrichment
No data.
EUVD