First published: Thu Nov 16 2023(Updated: )
Archery v1.10.0 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Archerydms Archery | =1.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-48053 is a vulnerability in Archery v1.10.0 that uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption.
CVE-2023-48053 can lead to the disclosure of information and communications in Archery v1.10.0.
The severity of CVE-2023-48053 is high with a CVSS score of 7.5.
Archery v1.9.0 is affected by CVE-2023-48053.
To fix CVE-2023-48053, update Archery to a version that has addressed the vulnerability.