ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution.
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/99242 | vdb entry third party advisory |
https://docs.expressionengine.com/v2/about/changelog.html#version-2-11-8 | vendor advisory |
https://hackerone.com/reports/215890 | permissions required |
https://docs.expressionengine.com/latest/about/changelog.html#version-3-5-5 | vendor advisory |
https://expressionengine.com/blog/expressionengine-3.5.5-and-2.11.8-released | vendor advisory |