CVE-2015-8013

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
25/07/2017
Last modified:
20/04/2025

Description

s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass authentication if message decryption is used as an authentication mechanism via a crafted symmetrically encrypted PGP message.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openpgpjs:openpgpjs:*:*:*:*:*:*:*:* 1.2.0 (including)