CVE-2017-20001

Severity CVSS v4.0:
Pending analysis
Type:
CWE-326 Inadequate Encryption Strength
Publication date:
01/01/2021
Last modified:
12/01/2021

Description

The AES encryption project 7.x and 8.x for Drupal does not sufficiently prevent attackers from decrypting data, aka SA-CONTRIB-2017-027. NOTE: This project is not covered by Drupal's security advisory policy.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:aes_encryption_project:aes_encryption:*:*:*:*:*:drupal:*:* 7.x-1.4 (including) 7.x-1.10 (including)
cpe:2.3:a:aes_encryption_project:aes_encryption:*:*:*:*:*:drupal:*:* 8.x-2.1 (including) 8.x-2.4 (including)


References to Advisories, Solutions, and Tools