Loading HuntDB...

GHSA-3gm7-8cfv-p8h9

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.

Related CVEs

Key Information

GHSA ID
GHSA-3gm7-8cfv-p8h9
Published
May 14, 2022 2:08 AM
Last Modified
February 16, 2024 9:31 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 30, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.