Man-in-the-Middle (MitM) Affecting paragonie/random_compat package, versions <2.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-PARAGONIERANDOMCOMPAT-72081
  • published1 Mar 2018
  • disclosed16 Mar 2016
  • creditUnknown

Introduced: 16 Mar 2016

CVE NOT AVAILABLE CWE-300  (opens in a new tab)

How to fix?

Upgrade paragonie/random_compat to version 2.0 or higher.

Overview

paragonie/random_compat is a PHP 5.x polyfill for random_bytes() and random_int() created and maintained by Paragon Initiative Enterprises.

Affected versions of this package are vulnerable to Man-in-the-Middle (MitM) due to using OpenSSL.

References

CVSS Scores

version 3.1