CVE-2021-30130: High severity phpseclib vulnerability
Published Apr 6, 2021
·Updated
Improper Certificate Validation in phpseclib
Other sources
phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.
— GitHub
Affected Software
9 affected componentsFixes available
composer/phpseclib/phpseclib<2.0.31, >=3.0.0, <3.0.7
composer/phpseclib/phpseclib<2.0.31
2.0.31
composer/phpseclib/phpseclib>=3.0.0<3.0.7
3.0.7
phpseclib phpseclib<2.0.31
phpseclib phpseclib>=3.0<3.0.7
Debian Debian Linux=10.0
debian/php-phpseclib
2.0.30-2+deb11u22.0.30-2+deb11u12.0.42-1+deb12u22.0.42-1+deb12u12.0.48-3
debian/php-phpseclib3
3.0.19-1+deb12u33.0.19-1+deb12u23.0.43-2
debian/phpseclib
1.0.19-3+deb11u21.0.19-3+deb11u11.0.20-1+deb12u21.0.20-1+deb12u11.0.23-6
Remediation
Patch Available
Event History
Apr 6, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
02:00 PM
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 6, 2025
Data Sourced
via Ubuntu·05:23 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·05:24 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-30130.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Improper Certificate Validation in phpseclib'.
3
What is the description of this vulnerability?
This vulnerability refers to phpseclib before 2.0.31 and 3.x before 3.0.7 mishandling RSA PKCS#1 v1.5 signature verification.
4
What is the severity of CVE-2021-30130?
The severity of CVE-2021-30130 is high with a CVSS score of 7.5.
5
What software versions are affected by this vulnerability?
The affected software versions include phpseclib 2.0.0 up to exclusive 2.0.31 and phpseclib 3.0.0 from inclusive up to exclusive 3.0.7.
6
How can I fix this vulnerability?
To fix this vulnerability, update your phpseclib package to version 2.0.31 or version 3.0.7.