spomky-labs/pki-framework is vulnerable to Improper Certificate Validation
74
High Risk
ACValidator::verifyIssuer() checks an attribute certificate signature without the signature algorithm and RSA key size policy that the same configuration uses for certificates in a certification path. An attribute certificate signed with MD5, or issued by a 512-bit RSA authority, is accepted even when policy forbids those algorithms and key sizes during path validation, so attributes from a weak or forged attribute authority are trusted. The fix enforces the configured algorithm and key size policy on the attribute certificate signature.
You are affected if you are using a version that falls within the vulnerable range and you validate attribute certificates with a configured signature algorithm or key size policy.
spomky-labs/pki-framework is vulnerable to Improper Certificate Validation in versions 1.0.0 - 1.6.1.
Upgrade the spomky-labs/pki-framework library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.