Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37565
HistoryOct 14, 2022 - 12:44 p.m.

Improper Access Control

2022-10-1412:44:57
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
23
openssl
vulnerability
access control
evp_md_init_internal
evp_cipher_init_internal
digest.c
evp_enc.c
attacker
evp_cipher_meth_new

0.001 Low

EPSS

Percentile

44.6%

openssl is vulnerable to improper access control. The vulnerability exists in evp_md_init_internal and evp_cipher_init_internal functions of digest.c and evp_enc.c respectively which allows an attacker to incorrectly pass NID_undef as this value in the call to EVP_CIPHER_meth_new().