Impact
The vulnerability causes the openSSL_encrypt library to store an unkeyed SHA‑256 hash of the plaintext in the file header metadata. An attacker who obtains an encrypted file can read this hash and confirm guessed plaintexts or fingerprint identical plaintexts across otherwise separate encrypted files, providing a covert means of verifying secrets without the encryption key.
Affected Systems
The jahlives:openssl_encrypt package, any version before 1.4.9, is affected. No additional vendor or product variants are listed in the advisory, so all deployments of these versions are at risk.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity issue. EPSS data is not available and the vuln is not yet listed in the CISA KEV catalog, but the exploitability is clear: an adversary who has access to an encrypted file can offline analyze the header to confirm plaintext guesses or detect duplicates. This represents a confidentiality breach that can aid further attacks, though it does not provide code execution or system takeover. The likelihood of exploitation is high where attackers can obtain encrypted documents and wish to validate guesses or identify repeated content.
OpenCVE Enrichment