目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2023-26154— PubNub 安全漏洞

CVSS 5.9 · Medium EPSS 0.95% · P58

可能的 ATT&CK 技术 1AI

T1557 · Adversary-in-the-Middle
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2023-26154 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
N/A
来源: CVE Program / CVE List V5
Vulnerability Description
Versions of the package pubnub before 7.4.0; all versions of the package com.pubnub:pubnub; versions of the package pubnub before 6.19.0; all versions of the package github.com/pubnub/go; versions of the package github.com/pubnub/go/v7 before 7.2.0; versions of the package pubnub before 7.3.0; versions of the package pubnub/pubnub before 6.1.0; versions of the package pubnub before 5.3.0; versions of the package pubnub before 0.4.0; versions of the package pubnub/c-core before 4.5.0; versions of the package com.pubnub:pubnub-kotlin before 7.7.0; versions of the package pubnub/swift before 6.2.0; versions of the package pubnub before 5.2.0; versions of the package pubnub before 4.3.0 are vulnerable to Insufficient Entropy via the getKey function, due to inefficient implementation of the AES-256-CBC cryptographic algorithm. The provided encrypt function is less secure when hex encoding and trimming are applied, leaving half of the bits in the key always the same for every encoded message or file. **Note:** In order to exploit this vulnerability, the attacker needs to invest resources in preparing the attack and brute-force the encryption.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
信息熵不充分
来源: CVE Program / CVE List V5
Vulnerability Title
PubNub 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
PubNub是PubNub开源的一个库。用于负责处理应用程序实时通信层所需的基础设施和 API。 PubNub存在安全漏洞,该漏洞源于AES-256-CBC加密算法的低效实现,容易通过getKey函数受到熵不足的影响。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
-pubnub 0 ~ 7.4.0 -
-com.pubnub:pubnub 0 ~ * -
-Pubnub 0 ~ 6.19.0 -
-github.com/pubnub/go 0 ~ * -
-github.com/pubnub/go/v7 0 ~ 7.2.0 -
-pubnub 0 ~ 7.3.0 -
-pubnub/pubnub 0 ~ 6.1.0 -
-pubnub 0 ~ 5.3.0 -
-pubnub 0 ~ 0.4.0 -
-pubnub/c-core 0 ~ 4.5.0 -
-com.pubnub:pubnub-kotlin 0 ~ 7.7.0 -
-pubnub/swift 0 ~ 6.2.0 -
-PubNub 0 ~ 5.2.0 -
-pubnub 0 ~ 4.3.0 -

二、漏洞 CVE-2023-26154 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2023-26154 的情报信息

登录查看更多情报信息。

CVE-2023-26154 补丁与修复 (1)

CVE-2023-26154 厂商安全公告 (12)

CVE-2023-26154 其他参考 (2)

同批安全公告 · n/a · 2023-12-06 · 共 12 条

CVE-2023-28875Afian FileRun 安全漏洞
CVE-2023-28876Afian FileRun 安全漏洞
CVE-2023-36655ProLion CryptoSpike 安全漏洞
CVE-2023-46353PrestaShop SQL注入漏洞
CVE-2023-46354PrestaShop 安全漏洞
CVE-2023-46751Artifex Software Ghostscript 安全漏洞
CVE-2023-48849Ruijie Networks RG-EG Series Routers 安全漏洞
CVE-2023-48930xinhu 安全漏洞
CVE-2023-48940DaiCuo 安全漏洞
CVE-2023-48123Netgate pfSense CE 安全漏洞
CVE-2023-48859TOTOLINK A3002RU 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2023-26154

暂无评论


发表评论