5
CVSSv2

CVE-2015-8013

Published: 25/07/2017 Updated: 10/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote malicious users to bypass authentication if message decryption is used as an authentication mechanism via a crafted symmetrically encrypted PGP message.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openpgpjs openpgpjs