nzo/url-encryptor-bundle
The NzoUrlEncryptorBundle is a Symfony Bundle used to Encrypt and Decrypt data and variables in the Web application or passed through URL
Activity
- Latest release
- 9mo ago
- Total releases
- 49
- Cadence
- ~2 months
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Jan 29, 2015
| Version | Released | |
|---|---|---|
v6.5.0
minor
| ||
v6.4.0
minor
| ||
v6.3.3
patch
| ||
v6.3.2
patch
| ||
v6.3.1
patch
| ||
v6.3.0
minor
| ||
v6.2.9
patch
| ||
v6.2.8
patch
| ||
v6.2.7
patch
| ||
v6.2.6
patch
| ||
v6.2.5
patch
| ||
v6.2.4
patch
| ||
v6.2.3
patch
| ||
v6.2.2
patch
| ||
v6.2.1
patch
| ||
v6.2.0
minor
| ||
v6.1.1
patch
| ||
v6.1.0
minor
| ||
v6.0.1
patch
| ||
v6.0.0
major
| ||
v5.2.0
minor
| ||
v4.5.0
minor
| ||
v4.4.0
minor
| ||
v5.1.0
minor
| ||
v4.3.2
patch
| ||
v5.0.1
patch
| ||
v4.3.1
patch
1 CVE
GHSA-r2r8-36pq-27cm
May 17, 2024
nzo/url-encryptor-bundle Insecure default secret key and IV allowing anyone to decrypt values
High
Versions of nzo/url-encryptor-bundle prior to 5.0.1 and 4.3.2 are affected by a security vulnerability related to the lack of mandatory key and IV requirements. By default, the bundle uses the aes-256-ctr algorithm, which is susceptible to malleability attacks, potentially leading to Insecure Direct Object Reference (IDOR) vulnerabilities. Additionally, the reuse of keys enables users to decrypt and modify encrypted data if they can guess the plaintext of one ciphertext. Affected versions
v5.0.0
4.1.0
4.2.0
4.2.1
v4.2.2
v4.2.3
v4.3.0
v4.3.1
Fixed in
4.3.2
5.0.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v5.0.0
major
1 CVE
GHSA-r2r8-36pq-27cm
May 17, 2024
nzo/url-encryptor-bundle Insecure default secret key and IV allowing anyone to decrypt values
High
Versions of nzo/url-encryptor-bundle prior to 5.0.1 and 4.3.2 are affected by a security vulnerability related to the lack of mandatory key and IV requirements. By default, the bundle uses the aes-256-ctr algorithm, which is susceptible to malleability attacks, potentially leading to Insecure Direct Object Reference (IDOR) vulnerabilities. Additionally, the reuse of keys enables users to decrypt and modify encrypted data if they can guess the plaintext of one ciphertext. Affected versions
v5.0.0
4.1.0
4.2.0
4.2.1
v4.2.2
v4.2.3
v4.3.0
v4.3.1
Fixed in
4.3.2
5.0.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v4.3.0
minor
1 CVE
GHSA-r2r8-36pq-27cm
May 17, 2024
nzo/url-encryptor-bundle Insecure default secret key and IV allowing anyone to decrypt values
High
Versions of nzo/url-encryptor-bundle prior to 5.0.1 and 4.3.2 are affected by a security vulnerability related to the lack of mandatory key and IV requirements. By default, the bundle uses the aes-256-ctr algorithm, which is susceptible to malleability attacks, potentially leading to Insecure Direct Object Reference (IDOR) vulnerabilities. Additionally, the reuse of keys enables users to decrypt and modify encrypted data if they can guess the plaintext of one ciphertext. Affected versions
v5.0.0
4.1.0
4.2.0
4.2.1
v4.2.2
v4.2.3
v4.3.0
v4.3.1
Fixed in
4.3.2
5.0.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v4.2.3
patch
1 CVE
GHSA-r2r8-36pq-27cm
May 17, 2024
nzo/url-encryptor-bundle Insecure default secret key and IV allowing anyone to decrypt values
High
Versions of nzo/url-encryptor-bundle prior to 5.0.1 and 4.3.2 are affected by a security vulnerability related to the lack of mandatory key and IV requirements. By default, the bundle uses the aes-256-ctr algorithm, which is susceptible to malleability attacks, potentially leading to Insecure Direct Object Reference (IDOR) vulnerabilities. Additionally, the reuse of keys enables users to decrypt and modify encrypted data if they can guess the plaintext of one ciphertext. Affected versions
v5.0.0
4.1.0
4.2.0
4.2.1
v4.2.2
v4.2.3
v4.3.0
v4.3.1
Fixed in
4.3.2
5.0.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v4.2.2
patch
1 CVE
GHSA-r2r8-36pq-27cm
May 17, 2024
nzo/url-encryptor-bundle Insecure default secret key and IV allowing anyone to decrypt values
High
Versions of nzo/url-encryptor-bundle prior to 5.0.1 and 4.3.2 are affected by a security vulnerability related to the lack of mandatory key and IV requirements. By default, the bundle uses the aes-256-ctr algorithm, which is susceptible to malleability attacks, potentially leading to Insecure Direct Object Reference (IDOR) vulnerabilities. Additionally, the reuse of keys enables users to decrypt and modify encrypted data if they can guess the plaintext of one ciphertext. Affected versions
v5.0.0
4.1.0
4.2.0
4.2.1
v4.2.2
v4.2.3
v4.3.0
v4.3.1
Fixed in
4.3.2
5.0.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
4.2.1
patch
1 CVE
GHSA-r2r8-36pq-27cm
May 17, 2024
nzo/url-encryptor-bundle Insecure default secret key and IV allowing anyone to decrypt values
High
Versions of nzo/url-encryptor-bundle prior to 5.0.1 and 4.3.2 are affected by a security vulnerability related to the lack of mandatory key and IV requirements. By default, the bundle uses the aes-256-ctr algorithm, which is susceptible to malleability attacks, potentially leading to Insecure Direct Object Reference (IDOR) vulnerabilities. Additionally, the reuse of keys enables users to decrypt and modify encrypted data if they can guess the plaintext of one ciphertext. Affected versions
v5.0.0
4.1.0
4.2.0
4.2.1
v4.2.2
v4.2.3
v4.3.0
v4.3.1
Fixed in
4.3.2
5.0.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
4.2.0
minor
1 CVE
GHSA-r2r8-36pq-27cm
May 17, 2024
nzo/url-encryptor-bundle Insecure default secret key and IV allowing anyone to decrypt values
High
Versions of nzo/url-encryptor-bundle prior to 5.0.1 and 4.3.2 are affected by a security vulnerability related to the lack of mandatory key and IV requirements. By default, the bundle uses the aes-256-ctr algorithm, which is susceptible to malleability attacks, potentially leading to Insecure Direct Object Reference (IDOR) vulnerabilities. Additionally, the reuse of keys enables users to decrypt and modify encrypted data if they can guess the plaintext of one ciphertext. Affected versions
v5.0.0
4.1.0
4.2.0
4.2.1
v4.2.2
v4.2.3
v4.3.0
v4.3.1
Fixed in
4.3.2
5.0.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
4.1.0
minor
1 CVE
GHSA-r2r8-36pq-27cm
May 17, 2024
nzo/url-encryptor-bundle Insecure default secret key and IV allowing anyone to decrypt values
High
Versions of nzo/url-encryptor-bundle prior to 5.0.1 and 4.3.2 are affected by a security vulnerability related to the lack of mandatory key and IV requirements. By default, the bundle uses the aes-256-ctr algorithm, which is susceptible to malleability attacks, potentially leading to Insecure Direct Object Reference (IDOR) vulnerabilities. Additionally, the reuse of keys enables users to decrypt and modify encrypted data if they can guess the plaintext of one ciphertext. Affected versions
v5.0.0
4.1.0
4.2.0
4.2.1
v4.2.2
v4.2.3
v4.3.0
v4.3.1
Fixed in
4.3.2
5.0.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
4.0
major
1 CVE
GHSA-r2r8-36pq-27cm
May 17, 2024
nzo/url-encryptor-bundle Insecure default secret key and IV allowing anyone to decrypt values
High
Versions of nzo/url-encryptor-bundle prior to 5.0.1 and 4.3.2 are affected by a security vulnerability related to the lack of mandatory key and IV requirements. By default, the bundle uses the aes-256-ctr algorithm, which is susceptible to malleability attacks, potentially leading to Insecure Direct Object Reference (IDOR) vulnerabilities. Additionally, the reuse of keys enables users to decrypt and modify encrypted data if they can guess the plaintext of one ciphertext. Affected versions
v5.0.0
4.1.0
4.2.0
4.2.1
v4.2.2
v4.2.3
v4.3.0
v4.3.1
Fixed in
4.3.2
5.0.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
3.1
minor
| ||
3.0
major
| ||
2.1
minor
| ||
2.0
major
| ||
1.9
minor
| ||
1.8
minor
| ||
1.7
minor
| ||
1.6
minor
| ||
1.5
minor
| ||
1.4
minor
| ||
1.3
minor
| ||
1.2
minor
| ||
1.1
minor
| ||
1.0
initial
|