CVE-2017-20001

The AES encryption project 7.x and 8.x for Drupal does not sufficiently prevent attackers from decrypting data, aka SA-CONTRIB-2017-027. NOTE: This project is not covered by Drupal’s security advisory policy.

Summary:

The AES encryption project 7.x and 8.x for Drupal does not sufficiently prevent attackers from decrypting data, aka SA-CONTRIB-2017-027. NOTE: This project is not covered by Drupal’s security advisory policy.

Reference Links(if available):

  • https://www.drupal.org/node/2857028
  • CVSS Score (if available)

    v2: / HIGH

    v3: /

    Links to Exploits(if available)